CVE-2026-40985: Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not configure or register the WebFlowELExpressionParser (avoid enabling the Unified EL parser) in applications using Spring Web Flow; remove or disable any existing configuration that registers this parser to prevent evaluation of untrusted Unified EL expressions.
Spring Web Flow WebFlowELExpressionParser configuration / Unified EL parser = not configured / disabled - Operational
Inventory and audit all applications that use Spring Web Flow to find any configuration of WebFlowELExpressionParser. For each affected application, remove or disable the parser configuration, test the application, and redeploy the fixed configuration. Monitor application behavior after deployment for anomalies.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40985?
The severity of CVE-2026-40985 is rated as medium with a score of 6.4.
How do I fix CVE-2026-40985?
To fix CVE-2026-40985, update your Spring Web Flow to versions 4.0.1 or higher, or to 3.0.2 or higher.
What types of applications are affected by CVE-2026-40985?
Applications that configure the WebFlowELExpressionParser in Spring Web Flow are affected by CVE-2026-40985.
What impact does CVE-2026-40985 have on affected systems?
CVE-2026-40985 can allow an attacker to execute malicious Unified EL expressions, potentially leading to sensitive data exposure.
Which versions of Spring Web Flow are vulnerable to CVE-2026-40985?
Spring Web Flow versions 4.0.0, 3.0.0 through 3.0.1, and 2.5.0 through 2.5.1 are vulnerable to CVE-2026-40985.