Junglewise Threat Intelligence

CVE-2026-40985: VMware Spring Web Flow EL injection in WebFlowELExpressionParser

CVE-2026-40985 · Severity: medium · CVSS 6.4 · Published 2026-06-11

Vendors: VMware.

Executive brief

Spring Web Flow is a framework used to build web applications with complex navigation flows. Applications that configure the WebFlowELExpressionParser component are vulnerable to expression language injection attacks through malicious Unified EL expressions. An attacker with low privileges and user interaction could execute arbitrary code, potentially leading to unauthorized data access or modification.

Technical details

The vulnerability is an expression language injection flaw (CWE-917) in the WebFlowELExpressionParser component of Spring Web Flow. The root cause is improper neutralization of special elements in Unified EL expressions, allowing attackers to inject malicious EL statements. The attack requires network access, low privileges, and user interaction. An attacker can achieve high confidentiality and integrity impact by executing arbitrary expressions within the context of the application. Patches are available: version 4.0.1 for 4.0.0; version 3.0.2 for 3.0.x; 2.5.x line has no official patch.

Affected products

  • Pivotal Software Spring Web Flow 4.0.0
  • Pivotal Software Spring Web Flow 3.0.0 through 3.0.1
  • Pivotal Software Spring Web Flow 2.5.0 through 2.5.1

Timeline

  • 2026-06-11: disclosed: Vulnerability disclosed on GitHub Advisory Database
  • 2026-08-18: advisory: GitHub security advisory reviewed and finalized

References

Related threats