Spring AI
VMware · 23 CVEs
RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure
Aug 27, 2026
Arbitrary File Write via Path Traversal in ResourceCacheService
Aug 27, 2026
Predictable cache directory location allows local ONNX model substitution in Spring AI
Aug 26, 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
Aug 26, 2026
DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection
Aug 21, 2026
Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
Aug 21, 2026
Unbounded persistent session allocation via repeated initialize requests
Aug 21, 2026
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector…
Jun 15, 2026
LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API
May 25, 2026
Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
May 12, 2026
ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
May 12, 2026
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitize…
May 9, 2026
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when h…
Apr 28, 2026
In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version…
Apr 28, 2026
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via…
Apr 28, 2026
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
Apr 28, 2026
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to…
Apr 28, 2026
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value f…
Mar 27, 2026
Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore
Mar 27, 2026
Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching
Mar 27, 2026
SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
Mar 27, 2026
CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
Mar 18, 2026
CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter
Mar 18, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-59319 | RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure | MEDIUM | 0.30% | Aug 27, 2026 |
| CVE-2026-59294 | Arbitrary File Write via Path Traversal in ResourceCacheService | MEDIUM | 0.36% | Aug 27, 2026 |
| CVE-2026-47852 | Predictable cache directory location allows local ONNX model substitution in Spring AI | HIGH | 0.35% | Aug 26, 2026 |
| CVE-2026-47851 | Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader | HIGH | 0.46% | Aug 26, 2026 |
| CVE-2026-59318 | DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection | CRITICAL | 0.25% | Aug 21, 2026 |
| CVE-2026-59308 | Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation | MEDIUM | 0.22% | Aug 21, 2026 |
| CVE-2026-59279 | Unbounded persistent session allocation via repeated initialize requests | HIGH | 0.55% | Aug 21, 2026 |
| CVE-2026-47835 | Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores | HIGH | 0.42% | Jun 15, 2026 |
| CVE-2026-41863 | LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API | MEDIUM | 0.41% | May 25, 2026 |
| CVE-2026-41713 | Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor | HIGH | 0.35% | May 12, 2026 |
| CVE-2026-41712 | ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage | HIGH | 0.41% | May 12, 2026 |
| CVE-2026-41705 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affecte… | HIGH | 0.39% | May 9, 2026 |
| CVE-2026-40980 | In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. A… | MEDIUM | 0.42% | Apr 28, 2026 |
| CVE-2026-40979 | In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.… | MEDIUM | 0.15% | Apr 28, 2026 |
| CVE-2026-40978 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions:… | HIGH | 0.44% | Apr 28, 2026 |
| CVE-2026-40966 | VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration | MEDIUM | 0.37% | Apr 28, 2026 |
| CVE-2026-40967 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages.… | HIGH | 0.39% | Apr 28, 2026 |
| CVE-2026-22744 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts th… | HIGH | 0.25% | Mar 27, 2026 |
| CVE-2026-22743 | Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore | HIGH | 0.25% | Mar 27, 2026 |
| CVE-2026-22742 | Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching | HIGH | 0.35% | Mar 27, 2026 |
| CVE-2026-22738 | SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution | CRITICAL | 1.09% | Mar 27, 2026 |
| CVE-2026-22729 | CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter | HIGH | 0.53% | Mar 18, 2026 |
| CVE-2026-22730 | CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter | HIGH | 0.52% | Mar 18, 2026 |
Showing 1 to 23 of 23 CVEs