CVE detail
CVE-2026-17459
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/383321/ctivuldb.com
No excerpt available.
Exploitvuldb.comJul 26, 2026, 11:16 AM - https://vuldb.com/vuln/383321vuldb.com
No excerpt available.
Exploitvuldb.comJul 26, 2026, 11:16 AM - https://vuldb.com/submit/862468vuldb.com
No excerpt available.
Exploitvuldb.comJul 26, 2026, 11:16 AM - https://vuldb.com/cve/CVE-2026-17459vuldb.com
No excerpt available.
Exploitvuldb.comJul 26, 2026, 11:16 AM No excerpt available.
Exploitgithub.comJul 26, 2026, 11:16 AM- https://github.com/perwendel/spark/github.com
No excerpt available.
Exploitgithub.comJul 26, 2026, 11:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14699CVSS 4.8 · Medium
A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathAllowed of the file src/Markdownify.ts. Executing a manipula…
- CVE-2026-52811CVSS 9.0 · Critical
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)…
- CVE-2026-8784CVSS 1.8 · Low
A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in symlink fol…
- CVE-2026-7832CVSS 6.4 · Medium
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink…
- CVE-2026-7397CVSS 1.9 · Low
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results i…
- CVE-2026-28684CVSS 6.6 · Medium
python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbo…