← Back

Spring Web Flow

spring_web_flow

Vendor: Broadcom • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Broadcom
1Spring Web Flow
Sep 4, 2026
Jun 11, 2026
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response fro...Show more
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.Show less
1Broadcom
1Spring Web Flow
Sep 4, 2026
Jun 11, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.