Known Vulnerabilities for Spring Web Flow by Spring
Listed below are 2 of the newest known vulnerabilities associated with "Spring Web Flow" by "Spring".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40986 json | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "tex... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-40985 json | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Aff... | Not Provided | 2026-06-11 | 2026-06-11 |