JavaScript Injection Vulnerability in Spring Framework by Pivotal
CVE-2026-41845

7.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41845?

A vulnerability exists in the Spring Framework due to improper escaping in JavaScriptUtils.javaScriptEscape(). This flaw may allow malicious actors to inject JavaScript code within the browser context, leading to potential cross-site scripting (XSS) attacks. Such vulnerabilities can compromise user sessions, redirect users to malicious sites, or perform actions on behalf of the user without consent. It is critical for users of affected versions to implement protective measures and update their systems promptly.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.