Cross-site scripting in Spring Framework - CVE-2026-41845
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.
The vulnerability exists due to incorrect escaping in JavaScriptUtils.javaScriptEscape() when processing input for JavaScript output. A remote attacker can supply crafted input to execute arbitrary script code in the victim's browser.
User interaction is required to load the affected content in a browser.
Affected software
Crowd Data Center
Jira Service Management Data Center
Jira Software Data Center
How to mitigate CVE-2026-41845
Crowd Data Center - update to 7.2.2
Jira Service Management Data Center - update to 11.3.8
Jira Software Data Center - update to 11.3.8