Spring Web Flow
94%
Total Score
89
94
92
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-302579 spring-webflow is vulnerable to Expression Language Injection in versions 0.0.1 - 3.0.1 and 4.0.0 - 4.0.0. | 0.0.1 - 3.0.14.0.0 - 4.0.0 | Medium |
CVE-2026-40986 org.springframework.webflow:spring-webflow is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.0 - 4.0.0, 3.0.0 - 3.0.1 and 0.0.0 - 2.5.1. | 0.0.0 - 2.5.13.0.0 - 3.0.14.0.0 - 4.0.0 | Medium |
CVE-2017-8039 org.springframework.webflow:spring-webflow is vulnerable to Insecure Default Initialization of Resource in versions 0.0.0 - 2.4.5. | 0.0.0 - 2.4.5 | Medium |
CVE-2017-4971 org.springframework.webflow:spring-webflow is vulnerable to Insecure Default Initialization of Resource in versions 2.4.0 - 2.4.4. | 2.4.0 - 2.4.4 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.webflow:spring-binding Version 4.0.1 | — | — |
org.springframework:spring-web Version 7.0.8 | — | — |
org.springframework:spring-webmvc Version 7.0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.