Количество 2
Количество 2
CVE-2026-40985
2 месяца назад
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
CVSS3: 6.4
EPSS: Низкий
GHSA-9ggw-87m9-9gfc
2 месяца назад
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
CVSS3: 6.4
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40985 Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. | CVSS3: 6.4 | 0% Низкий | 2 месяца назад | |
GHSA-9ggw-87m9-9gfc Spring Web Flow has Data Binding Vulnerability with Unified EL Parser | CVSS3: 6.4 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу
20