CVE-2026-40986: Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40986?
The severity of CVE-2026-40986 is medium with a score of 4.8.
What type of vulnerability is CVE-2026-40986?
CVE-2026-40986 is categorized as an XSS (Cross-Site Scripting) vulnerability.
How can I mitigate CVE-2026-40986?
To mitigate CVE-2026-40986, ensure that your Spring Web Flow is updated to a patched version that addresses this vulnerability.
What is the risk associated with CVE-2026-40986?
CVE-2026-40986 carries a risk of scripting attacks in the user's browser if the error response contains attacker-reflected input.
What software is affected by CVE-2026-40986?
CVE-2026-40986 affects the Spring Web Flow component of the Spring framework.