What is CVE-2026-17459?
A symlink following vulnerability was found in the staticFiles.externalLocation function of the SparkJava component in perwendel spark up to version 2.9.4. This allows attackers to manipulate symbolic links through the ExternalResourceHandler.java file. Users are advised to apply security updates.
Azərbaycanca: perwendel spark 2.9.4-ə qədər versiyalarda SparkJava komponentinin ExternalResourceHandler.java faylında staticFiles.externalLocation funksiyasında symlink following zəifliyi aşkar edilib. Bu, təcavüzkarın manipulyasiya ilə simvolik keçidləri izləməsinə imkan yaradır. İstifadəçilərə təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Through which file can CVE-2026-17459 be exploited?
Through the ExternalResourceHandler.java file.
Which versions of perwendel spark are affected by CVE-2026-17459?
This vulnerability affects perwendel spark up to version 2.9.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.