CVE-2026-40985Medium· 6.4▾ SunlitApplications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
spring_web_flow < 2.5.2spring_web_flow >= 3.0.0, < 3.0.1.1spring_web_flow = 4.0.0Upgrade past the affected range:
spring_web_flow 3.0.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2017-4971Medium· 5.9An issue was discovered in Pivotal Spring Web Flow through 2.4.4
CVE-2017-8039Medium· 5.9An issue was discovered in Pivotal Spring Web Flow through 2.4.5
CVE-2026-40986Medium· 4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server cont…
CVE-2026-41719Medium· 6.4A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValu…
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-40477Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments