A vulnerability classified as critical was found in perwendel spark up to 2.9.4. This vulnerability affects the function
staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following.
This vulnerability is registered as CVE-2026-17459. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.