« Volver al listado

CVE-2026-40986

Estado: AnalizadaMedia (4.8)—

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.

Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-40986",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-40986",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T12:46:39.516114Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Web Flow",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.0.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.0.0",
              "lessThan": "3.0.1.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.5.0",
              "lessThan": "2.5.2",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-11T07:16:26.920",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-40986",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not \"text/html\", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker.\n\nAffected versions:\nSpring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1."
    },
    {
      "lang": "es",
      "value": "El RemotingHandler de JavaScript de Spring Web Flow renderiza el cuerpo de una respuesta de error como HTML incluso cuando la respuesta no es 'text/html', lo que puede resultar en un ataque de scripting en el navegador del usuario si la respuesta de error del servidor contiene detalles de error con entrada reflejada de un atacante.\n\nVersiones afectadas:\nSpring Web Flow 4.0.0; 3.0.0 a 3.0.1; 2.5.0 a 2.5.1."
    }
  ],
  "lastModified": "2026-09-04T18:11:51.270",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:spring_web_flow:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AD1649A-0A75-4F05-9C73-D08D24A9A5D5",
              "versionEndExcluding": "2.5.2"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:spring_web_flow:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1107F4C-EBDC-4024-A99F-A739AE3625A0",
              "versionEndExcluding": "3.0.1.1",
              "versionStartIncluding": "3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:spring_web_flow:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85B5CA38-4D2A-4367-A735-ABAB927D4B13"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}