VYPR

Maven package

org.springframework.webflow/spring-webflow

pkg:maven/org.springframework.webflow/spring-webflow

Vulnerabilities (4)

  • CVE-2026-40986MedJun 11, 2026
    affected >= 4.0.0, < 4.0.1fixed 4.0.1

    Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fro

  • CVE-2026-40985MedJun 11, 2026
    affected >= 4.0.0, < 4.0.1fixed 4.0.1

    Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

  • CVE-2017-8039MedNov 27, 2017
    affected < 2.4.6fixed 2.4.6

    An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that

  • CVE-2017-4971MedJun 13, 2017
    affected >= 2.4.0, < 2.4.5fixed 2.4.5

    An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that