CVE-2026-41845: Spring Framework Cross-site Scripting via JavaScriptUtils
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41845?
CVE-2026-41845 has a severity rating of high, with a score of 7.1.
How do I fix CVE-2026-41845?
To fix CVE-2026-41845, upgrade to Spring Framework versions 7.0.8 or higher, 6.2.19 or higher, or 6.1.28 or higher.
What types of vulnerabilities are associated with CVE-2026-41845?
CVE-2026-41845 is associated with cross-site scripting (XSS) and code injection vulnerabilities.
Which versions of the Spring Framework are affected by CVE-2026-41845?
CVE-2026-41845 affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, and 6.1.0 through 6.1.27.
What is the impact of CVE-2026-41845?
The impact of CVE-2026-41845 can lead to JavaScript code injection in the browser, potentially enabling an attacker to execute malicious scripts.