CVE-2026-40985: Broadcom Spring Web Flow
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Affected products
- Broadcom Spring Web Flow: before 2.5.2 (fixed in 2.5.2); from 3.0.0, before 3.0.1.1 (fixed in 3.0.1.1); version 4.0.0 only
Published 2026-06-11. Last modified 2026-09-04.