6.4
CVE-2026-40985
- EPSS 0.23%
- Veröffentlicht 11.06.2026 05:16:33
- Zuletzt bearbeitet 04.09.2026 18:12:31
- Erkennungen
Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Spring Web Flow Version < 2.5.2
Broadcom ≫ Spring Web Flow Version >= 3.0.0 < 3.0.1.1
Broadcom ≫ Spring Web Flow Version 4.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.129 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 6.4 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
|
CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
https://spring.io/security/cve-2026-40985