MEDIUM | JUNE 10, 2026 | CVE-2026-40986
Description
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.
Pre-conditions:
- The application uses the "org.springframework.webflow:spring-js-resources" artifact.
- Spring-Dojo.js loaded and used for Ajax requests.
Affected Spring Products and Versions
Spring Web Flow:
- 4.0.0 - 4.0.0
- 3.0.0 - 3.0.1
- 2.5.0 - 2.5.1
- Older, unsupported versions are also affected.
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 4.0.x | 4.0.1 | OSS |
| 4.0.0.1 | Enterprise Support Only | |
| 3.0.x | 3.0.2 | OSS |
| 3.0.1.1 | Enterprise Support Only | |
| 2.5.x | 2.5.2 | Enterprise Support Only |
No further mitigation steps are necessary.
References
History
- 2026-06-10: Initial vulnerability report published.
Reporting a vulnerability
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy













