Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-40985 |
|
Thu, 11 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Web Flow |
|
| Vendors & Products |
Spring
Spring spring Web Flow |
Thu, 11 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. | |
| Title | Data Binding Vulnerability in Spring Web Flow with Unified EL Parser | |
| Weaknesses | CWE-917 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-23T19:09:40.302Z
Reserved: 2026-04-16T02:19:09.388Z
Link: CVE-2026-40985
Updated: 2026-06-11T12:47:06.460Z
Status : Awaiting Analysis
Published: 2026-06-11T05:16:33.757
Modified: 2026-06-11T15:21:30.653
Link: CVE-2026-40985
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:27Z