GHSA-9ggw-87m9-9gfcMediumCVSS 6.4

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

Published
June 11, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.

Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

🎯 Affected products3

  • maven/org.springframework.webflow:spring-webflow:= 4.0.0
  • maven/org.springframework.webflow:spring-webflow:>= 3.0.0, < 3.0.2
  • maven/org.springframework.webflow:spring-webflow:<= 2.5.1

🔗 References (3)