VYPR

Web Flow

by Spring Projects

CVEs (1)

  • CVE-2026-40985MedJun 11, 2026
    risk 0.42cvss 6.4epss

    Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.