MEDIUM | JUNE 10, 2026 | CVE-2026-40985
Description
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Pre-conditions:
- The application explicitly configures the
WebFlowELExpressionParseror its base class "ELExpressionParser". - The
useSpringBindingconfiguration property has not been set totrue. - View states do not use the
<binding>element on a view state to declare the properties to bind.
Affected Spring Products and Versions
Spring Web Flow:
- 4.0.0 - 4.0.0
- 3.0.0 - 3.0.1
- 2.5.0 - 2.5.1
- Older, unsupported versions are also affected.
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.0.x | 4.0.1 | OSS |
| 4.0.0.1 | Enterprise Support Only | |
| 3.0.x | 3.0.2 | OSS |
| 3.0.1.1 | Enterprise Support Only | |
| 2.5.x | 2.5.2 | Enterprise Support Only |
No further mitigation steps are necessary.
References
History
- 2026-06-10: Initial vulnerability report published.
Reporting a vulnerability
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy













