CVE-2026-40986
Estado: AnalizadaMedia (4.8)—
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.
Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-40986",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-40986",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-11T12:46:39.516114Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@vmware.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "Spring",
"product": "Spring Web Flow",
"versions": [
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.0.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.0.0",
"lessThan": "3.0.1.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.5.0",
"lessThan": "2.5.2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-11T07:16:26.920",
"references": [
{
"url": "https://spring.io/security/cve-2026-40986",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not \"text/html\", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.\n\nAffected versions:\nSpring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1."
},
{
"lang": "es",
"value": "El RemotingHandler de JavaScript de Spring Web Flow renderiza el cuerpo de una respuesta de error como HTML incluso cuando la respuesta no es 'text/html', lo que puede resultar en un ataque de scripting en el navegador del usuario si la respuesta de error del servidor contiene detalles de error con entrada reflejada de un atacante.\n\nVersiones afectadas:\nSpring Web Flow 4.0.0; 3.0.0 a 3.0.1; 2.5.0 a 2.5.1."
}
],
"lastModified": "2026-09-04T18:11:51.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:broadcom:spring_web_flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2AD1649A-0A75-4F05-9C73-D08D24A9A5D5",
"versionEndExcluding": "2.5.2"
},
{
"criteria": "cpe:2.3:a:broadcom:spring_web_flow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1107F4C-EBDC-4024-A99F-A739AE3625A0",
"versionEndExcluding": "3.0.1.1",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:broadcom:spring_web_flow:4.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85B5CA38-4D2A-4367-A735-ABAB927D4B13"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}