CVE-2024-38816
Spring path traversal - functional web resource handlers serve files outside the configured location
- Severity
- high
- Affected product
- Spring Framework
- Affected versions
- Spring Framework ≥ 5.3.0, < 5.3.40
- Affected versions
- Spring Framework ≥ 6.0.0, < 6.0.24
- Affected versions
- Spring Framework ≥ 6.1.0, < 6.1.13
- Fixed in
- Spring Framework 5.3.40
- Fixed in
- Spring Framework 6.0.24
- Fixed in
- Spring Framework 6.1.13
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Spring Framework from its response and reports this CVE when the detected version falls inside the affected range below.
Branch boundaries per the VMware advisory (5.3.40 / 6.0.24 / 6.1.13); treated as provisional and reported as a version match.
COMPONENT VERSION RANGE
NewScan fingerprints Spring Framework from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
COMPONENT VERSION RANGE
NewScan fingerprints Spring Framework from its response and reports this CVE when the detected version falls inside the affected range below.
Backfilled 2026-08-02 (docs/todo.md item 1).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →