JavaScript RemotingHandler Vulnerability in Spring Web Flow by Pivotal Software
CVE-2026-40986

4.8MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-40986?

A security issue in Spring Web Flow's JavaScript RemotingHandler allows error responses to be improperly rendered as HTML, leading to potential scripting attacks in users' browsers. This vulnerability arises when server error details, potentially influenced by an attacker, are reflected in responses not intended to be HTML. It exposes users to the risk of executing malicious scripts, creating a serious concern for the integrity and security of applications using affected versions of Spring Web Flow.

Affected Version(s)

Spring Web Flow 4.0.0 < 4.0.0.1

Spring Web Flow 3.0.0 < 3.0.1.1

Spring Web Flow 2.5.0 < 2.5.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.