JavaScript RemotingHandler Vulnerability in Spring Web Flow by Pivotal Software
CVE-2026-40986
4.8MEDIUM
What is CVE-2026-40986?
A security issue in Spring Web Flow's JavaScript RemotingHandler allows error responses to be improperly rendered as HTML, leading to potential scripting attacks in users' browsers. This vulnerability arises when server error details, potentially influenced by an attacker, are reflected in responses not intended to be HTML. It exposes users to the risk of executing malicious scripts, creating a serious concern for the integrity and security of applications using affected versions of Spring Web Flow.
Affected Version(s)
Spring Web Flow 4.0.0 < 4.0.0.1
Spring Web Flow 3.0.0 < 3.0.1.1
Spring Web Flow 2.5.0 < 2.5.2
