Spring / Spring AI
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59319 | RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure | MEDIUM | 4.3 | Aug 27, 2026 |
| CVE-2026-59294 | Arbitrary File Write via Path Traversal in ResourceCacheService | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-47852 | Predictable cache directory location allows local ONNX model substitution in Spring AI | HIGH | 7.5 | Aug 26, 2026 |
| CVE-2026-47851 | Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader | HIGH | 7.5 | Aug 26, 2026 |
| CVE-2026-59318 | DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection | CRITICAL | 9.8 | Aug 21, 2026 |
| CVE-2026-59308 | Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation | MEDIUM | 4.3 | Aug 21, 2026 |
| CVE-2026-59279 | Unbounded persistent session allocation via repeated initialize requests | HIGH | 7.5 | Aug 21, 2026 |
| CVE-2026-47835 | Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores | HIGH | 8.6 | Jun 15, 2026 |
| CVE-2026-41863 | LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API | MEDIUM | 6.5 | May 25, 2026 |
| CVE-2026-41705 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affecte… | HIGH | 8.6 | May 9, 2026 |
| CVE-2026-40980 | In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. A… | MEDIUM | 6.5 | Apr 28, 2026 |
| CVE-2026-40979 | In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.… | MEDIUM | 6.1 | Apr 28, 2026 |
| CVE-2026-40978 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions:… | HIGH | 8.8 | Apr 28, 2026 |
| CVE-2026-40967 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages.… | HIGH | 8.6 | Apr 28, 2026 |
| CVE-2026-22744 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts th… | HIGH | 7.5 | Mar 27, 2026 |
| CVE-2026-22743 | Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore | HIGH | 7.5 | Mar 27, 2026 |
| CVE-2026-22742 | Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching | HIGH | 8.6 | Mar 27, 2026 |
| CVE-2026-22738 | SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution | CRITICAL | 9.8 | Mar 27, 2026 |
Showing 1 to 18 of 18 CVEs