Cross-Site Scripting Vulnerability in Spring Framework by Spring
CVE-2026-41846
5.9MEDIUM
What is CVE-2026-41846?
Spring MVC applications that incorporate user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags may be susceptible to arbitrary HTML and JavaScript code injection. This could lead to the execution of malicious scripts in the context of the affected application, creating the potential for a cross-site scripting (XSS) attack that impacts the security of both the application and its users.
Affected Version(s)
Spring Framework 7.0.0 < 7.0.7.1
Spring Framework 6.2.0 < 6.2.18.1
Spring Framework 6.1.0 < 6.1.28
