Broadcom Spring Web Flow — known CVE vulnerabilities
Every CVE whose affected-product data names Broadcom Spring Web Flow, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2026-40985 — CVSS 6.4 (medium): Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions…
CVE-2017-4971 — CVSS 5.9 (medium): An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator…
CVE-2017-8039 — CVSS 5.9 (medium): An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator…
CVE-2026-40986 — CVSS 4.8 (medium): Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which…