Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.webflow/spring-webflow
  4. ›
  5. CVE-2026-40986

CVE-2026-40986: Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

June 11, 2026 (updated August 18, 2026)

Spring Web Flow’s JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not “text/html”, which can result in a scripting attack in the user’s browser if the error response from the server contains error details with input reflected from an attacker.

Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

References

  • github.com/advisories/GHSA-hw5c-xm3c-v96w
  • nvd.nist.gov/vuln/detail/CVE-2026-40986
  • spring.io/security/cve-2026-40986

Code Behaviors & Features

Detect and mitigate CVE-2026-40986 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.5.1, all versions starting from 3.0.0 before 3.0.2, all versions starting from 4.0.0 before 4.0.1

Fixed versions

  • 3.0.2
  • 4.0.1

Solution

Upgrade to versions 3.0.2, 4.0.1 or above.

Impact 4.8 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

maven/org.springframework.webflow/spring-webflow/CVE-2026-40986.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 21 Aug 2026 00:19:59 +0000.