CVE-2026-40985: Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
(updated )
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-40985 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →