CVE-2026-40985: Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
Published Jun 11, 2026
·Updated
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Affected Software
4 affected components
Spring Spring Web Flow=4.0.0, >=3.0.0<=3.0.1, >=2.5.0<=2.5.1
Broadcom Spring Web Flow<2.5.2
Broadcom Spring Web Flow>=3.0.0<3.0.1.1
Broadcom Spring Web Flow=4.0.0
Event History
Jun 11, 2026
CVE Published
via MITRE·05:02 AM
Data Sourced
via MITRE·05:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40985?
The severity of CVE-2026-40985 is rated as medium with a score of 6.4.
2
How do I fix CVE-2026-40985?
To fix CVE-2026-40985, update your Spring Web Flow to versions 4.0.1 or higher, or to 3.0.2 or higher.
3
What types of applications are affected by CVE-2026-40985?
Applications that configure the WebFlowELExpressionParser in Spring Web Flow are affected by CVE-2026-40985.
4
What impact does CVE-2026-40985 have on affected systems?
CVE-2026-40985 can allow an attacker to execute malicious Unified EL expressions, potentially leading to sensitive data exposure.
5
Which versions of Spring Web Flow are vulnerable to CVE-2026-40985?
Spring Web Flow versions 4.0.0, 3.0.0 through 3.0.1, and 2.5.0 through 2.5.1 are vulnerable to CVE-2026-40985.