CVE-2026-56122
HIGHWinstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths
Title source: cnaDescription
Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot. Attackers can traverse outside the webroot directory using traversal-prefixed paths in a single HTTP request to read any file accessible to the servlet engine process, including sensitive system files when the service runs with elevated privileges.
References (3)
Core 3
Core References
Exploit technical-description
exploit
https://gist.github.com/VAMorales/ce93f10215c43b2a8344426f4dd59cd3
Product product
https://winstone.sourceforge.net/
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/winstone-servlet-engine-path-traversal-via-http-request-paths
Scores
CVSS v3
7.5
EPSS
0.0038
EPSS Percentile
30.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
rickknowles/Winstone Servlet Container
< 0.9.10
Published
Jun 25, 2026
Tracked Since
Jun 25, 2026