VendorsVMwarespring_aiall versions
Vulnerabilities

VMware Spring AI

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2026-22738
SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution
Published 2026-03-27 · Modified
9.8EPSS 0.011
CVE-2026-59318
DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection
Published 2026-08-21 · Analyzed
9.8EPSS 0.002
CVE-2026-22730
CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter
Published 2026-03-18 · Analyzed
8.8EPSS 0.005
CVE-2026-40978
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
Published 2026-04-28 · Analyzed
8.8EPSS 0.003
CVE-2026-22729
CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
Published 2026-03-18 · Analyzed
8.6EPSS 0.005
CVE-2026-40967
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
Published 2026-04-28 · Analyzed
8.6EPSS 0.004
CVE-2026-41705
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater.
Published 2026-05-09 · Analyzed
8.6EPSS 0.004
CVE-2026-22742
Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching
Published 2026-03-27 · Modified
8.6EPSS 0.004
CVE-2026-47835
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
Published 2026-06-15 · Analyzed
8.6EPSS 0.003
CVE-2026-41713
Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
Published 2026-05-12 · Analyzed
8.2EPSS 0.002
CVE-2026-59279
Unbounded persistent session allocation via repeated initialize requests
Published 2026-08-21 · Analyzed
7.5EPSS 0.004
CVE-2026-47851
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
Published 2026-08-26 · Analyzed
7.5EPSS 0.003
CVE-2026-41712
ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
Published 2026-05-12 · Analyzed
7.5EPSS 0.003
CVE-2026-22744
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Published 2026-03-27 · Modified
7.5EPSS 0.003
CVE-2026-22743
Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore
Published 2026-03-27 · Analyzed
7.5EPSS 0.003
CVE-2026-47852
Predictable cache directory location allows local ONNX model substitution in Spring AI
Published 2026-08-26 · Analyzed
7.5EPSS 0.002
CVE-2026-41863
LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API
Published 2026-05-25 · Analyzed
6.5EPSS 0.004
CVE-2026-59294
Arbitrary File Write via Path Traversal in ResourceCacheService
Published 2026-08-27 · Analyzed
6.5EPSS 0.003
CVE-2026-40980
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
Published 2026-04-28 · Analyzed
6.5EPSS 0.002
CVE-2026-40979
In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
Published 2026-04-28 · Analyzed
6.1EPSS 0.001
CVE-2026-40966
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
Published 2026-04-28 · Analyzed
5.9EPSS 0.002
CVE-2026-59319
RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure
Published 2026-08-27 · Analyzed
4.3EPSS 0.002
CVE-2026-59308
Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
Published 2026-08-21 · Analyzed
4.3EPSS 0.002