Maven package
org.springframework.webflow/spring-webflow
pkg:maven/org.springframework.webflow/spring-webflow
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-40986 | Med | 4.8 | >= 4.0.0, < 4.0.1 | 4.0.1 | Jun 11, 2026 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fro | |
| CVE-2026-40985 | Med | 6.4 | >= 4.0.0, < 4.0.1 | 4.0.1 | Jun 11, 2026 | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. | |
| CVE-2017-8039 | Med | 5.9 | < 2.4.6 | 2.4.6 | Nov 27, 2017 | An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that | |
| CVE-2017-4971 | Med | 5.9 | >= 2.4.0, < 2.4.5 | 2.4.5 | Jun 13, 2017 | An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that |
- affected >= 4.0.0, < 4.0.1fixed 4.0.1
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected fro
- affected >= 4.0.0, < 4.0.1fixed 4.0.1
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
- affected < 2.4.6fixed 2.4.6
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that
- affected >= 2.4.0, < 2.4.5fixed 2.4.5
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that