CVE-2026-40986: Broadcom Spring Web Flow
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
Affected products
- Broadcom Spring Web Flow: before 2.5.2 (fixed in 2.5.2); from 3.0.0, before 3.0.1.1 (fixed in 3.0.1.1); version 4.0.0 only
Published 2026-06-11. Last modified 2026-09-04.