Vulnerability in Spring Web Flow Affects Multiple Versions
CVE-2026-40985
6.4MEDIUM
What is CVE-2026-40985?
Applications that utilize the WebFlowELExpressionParser in Spring Web Flow are at risk due to improper handling of Unified EL expressions. This vulnerability enables attackers to craft malicious expressions that can be executed within the application context, potentially leading to unauthorized access or code execution. It is critical for developers using affected versions to promptly assess their systems and apply the necessary updates to mitigate this security risk.
Affected Version(s)
Spring Web Flow 4.0.0 < 4.0.0.1
Spring Web Flow 3.0.0 < 3.0.1.1
Spring Web Flow 2.5.0 < 2.5.2
