Vulnerability in Spring Web Flow Affects Multiple Versions
CVE-2026-40985

6.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-40985?

Applications that utilize the WebFlowELExpressionParser in Spring Web Flow are at risk due to improper handling of Unified EL expressions. This vulnerability enables attackers to craft malicious expressions that can be executed within the application context, potentially leading to unauthorized access or code execution. It is critical for developers using affected versions to promptly assess their systems and apply the necessary updates to mitigate this security risk.

Affected Version(s)

Spring Web Flow 4.0.0 < 4.0.0.1

Spring Web Flow 3.0.0 < 3.0.1.1

Spring Web Flow 2.5.0 < 2.5.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.