Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:NDefault status
unaffected
4.0.0 (custom) before 4.0.1
affected
3.0.0 (custom) before 3.0.2
affected
2.5.0 (custom) before 2.5.2
affected
Description
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Problem types
CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement
Product status
4.0.0 (custom) before 4.0.1
3.0.0 (custom) before 3.0.2
2.5.0 (custom) before 2.5.2
References
spring.io/security/cve-2026-40985