Junglewise Threat Intelligence

CVE-2026-41846: VMware Spring Framework XSS in JSP form tags

CVE-2026-41846 · Severity: medium · CVSS 5.9 · Published 2026-06-09

Technologies: VMware Spring Framework. Vendors: VMware.

Executive brief

Spring Framework is a widely used tool for building Java-based web applications. A security flaw in its web component allows attackers to inject malicious scripts into web pages if the application uses certain form tags with user-provided styling information. This could lead to unauthorized actions being performed in a user's browser or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Spring MVC's JSP form tag library. The root cause is the improper neutralization of input within the 'cssClass', 'cssErrorClass', and 'cssStyle' attributes of JSP form tags. An attacker can exploit this by providing malicious HTML or JavaScript code that is subsequently rendered by the server without adequate escaping. Exploitation requires the application to accept user-controlled strings for these specific attributes and typically involves user interaction (UI:R). Patches are available in versions 7.0.8 and 6.2.19, with updates also provided for the 6.1.x and 5.3.x branches.

Affected products

  • VMware Spring Framework 7.0.0 to 7.0.7, 6.2.0 to 6.2.18, 6.1.0 to 6.1.27, 5.3.0 to 5.3.48

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory
  • 2026-07-30: patched: Updated advisory with patch information

References

Related threats