VYPR

Web Flow

by Spring Projects

CVEs (2)

  • CVE-2026-40985MedJun 11, 2026
    risk 0.42cvss 6.4epss 0.00

    Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

  • CVE-2026-40986MedJun 11, 2026
    risk 0.31cvss 4.8epss 0.00

    Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected…