Cross-Site Scripting Vulnerability in Spring Framework by Spring
CVE-2026-41846

5.9MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41846?

Spring MVC applications that incorporate user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags may be susceptible to arbitrary HTML and JavaScript code injection. This could lead to the execution of malicious scripts in the context of the affected application, creating the potential for a cross-site scripting (XSS) attack that impacts the security of both the application and its users.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.