VulnSea

spring_web_flow vulnerabilities

CVEs whose affected-version data names the spring_web_flow package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-40986Medium· 4.8
3mo ago

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server cont…

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server cont…

Sunlitbroadcom · spring_web_flowEPSS 0.21%via NVD
CVE-2026-40985Medium· 6.4
3mo ago

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Sunlitbroadcom · spring_web_flowEPSS 0.23%via NVD
CVE-2017-8039Medium· 5.9
8y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.5

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

Sunlitbroadcom · spring_web_flowEPSS 0.95%via NVD
CVE-2017-4971Medium· 5.9PoC
9y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.4

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

Twilightbroadcom · spring_web_flowEPSS 12%via NVD
spring_web_flow vulnerabilities (CVEs) · VulnSea