Unknown · Winstone Servlet Engine · CVE-2026-56122
**Name of the Vulnerable Software and Affected Versions**
Winstone Servlet Engine versions prior to 0.9.11
**Description**
A path traversal flaw exists when serving static files from the configured webroot. Unauthenticated attackers can read arbitrary files accessible to the servlet engine process, including sensitive system files if the service runs with elevated privileges, by sending HTTP GET requests containing unsanitized dot-dot-slash sequences.
**Recommendations**
Update Winstone Servlet Engine to version 0.9.11 or later.