CVE-2026-40966
published 2026-04-28CVE-2026-40966: In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and…
PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.23%
14.1th percentile
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | spring_ai | >= 1.0.0 < 1.0.6 | 1.0.6 |
| vmware | spring_ai | >= 1.1.0 < 1.1.5 | 1.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring AI up to 1.0.5/1.1.4 Conversation access control
vuldb·2026-04-28·CVSS 5.9
CVE-2026-40966 [MEDIUM] Vmware Spring AI up to 1.0.5/1.1.4 Conversation access control
A vulnerability identified as critical has been detected in Vmware Spring AI up to 1.0.5/1.1.4. This issue affects some unknown processing of the component Conversation Handler. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2026-40966. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
ghsa·2026-04-28
CVE-2026-40966 [MEDIUM] CWE-284 Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published