THREAT OPS › Threat News › [GHSA] GHSA-g29j-rwfv-h99w (high) — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
[GHSA] GHSA-g29j-rwfv-h99w (high) — Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
GHSA-g29j-rwfv-h99w Severity: high CVE: CVE-2026-63490
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
### Summary `com.github.jknack.handlebars.springmvc.SpringTemplateLoader` resolves Spring MVC view names into URLs via Spring's `ResourceLoader` **without applying the path-containment check** that protects every other URL-based loader in the projec
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-63490cve
- java.iodomain
Original source: https://github.com/advisories/GHSA-g29j-rwfv-h99w