216.73.217.172

CVE-2026-40985

· Published 11/06/2026 07:16 · Modified 11/06/2026 15:21 · Author: The MITRE Corporation

Labels: CVE-2026-40985 2026-06-11CVE-2026-40985CWE-917[email protected]

Essential information

Published
11/06/2026 07:16
Modified
11/06/2026 15:21
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
6.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CWE-917
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
spring / spring web flow cpe:2.3:a:spring:spring_web_flow:4.0.0:*:*:*:*:*:*:*
spring / spring web flow cpe:2.3:a:spring:spring_web_flow:3.0.0-3.0.1:*:*:*:*:*:*:*
spring / spring web flow cpe:2.3:a:spring:spring_web_flow:2.5.0-2.5.1:*:*:*:*:*:*:*

References