Spring Ai vulnerabilities
18 known vulnerabilities affecting spring/spring_ai.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2026-22738P2CRITICALCVSS 9.8≥ 1.0.0, < 1.0.5≥ 1.1.0, < 1.1.42026-03-27
CVE-2026-22738 [CRITICAL] CWE-917 CVE-2026-22738: In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected.
This issue affects Spring AI: from
nvd
CVE-2026-40978P3HIGHCVSS 8.8≥ 1.0.0, < 1.0.6≥ 1.1.0, < 1.1.52026-04-28
CVE-2026-40978 [HIGH] CWE-89 CVE-2026-40978: SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitra
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs.
Affected versions:
Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
nvd
CVE-2026-22742P3HIGHCVSS 8.6≥ 1.0.0, < 1.0.5≥ 1.1.0, < 1.1.42026-03-27
CVE-2026-22742 [HIGH] CWE-918 CVE-2026-22742: Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability i
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations.
This
nvd
CVE-2026-47835P3HIGHCVSS 8.6≥ 1.0.0, < 1.0.9≥ 1.1.0, < 1.1.82026-06-15
CVE-2026-47835 [HIGH] CWE-943 CVE-2026-47835: In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary que
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store.
Affected versions:
Spring AI 1.0.0 through 1.0.x (fix 1.0.9).
Spring AI 1.1.0 through 1.1.
nvd
CVE-2026-40967P3HIGHCVSS 8.6≥ 1.0.0, < 1.0.6≥ 1.1.0, < 1.1.52026-04-28
CVE-2026-40967 [HIGH] CWE-94 CVE-2026-40967: In Spring AI, various FilterExpressionConverter implementations accept a filter expression object an
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query.
Affected versions:
Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5
nvd
CVE-2026-41705P3HIGHCVSS 8.6≥ 1.0.0, < 1.0.7≥ 1.1.0, < 1.1.62026-05-09
CVE-2026-41705 [HIGH] CWE-917 CVE-2026-41705: Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injec
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs.
Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater.
nvd
CVE-2026-22743P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.5≥ 1.1.0, < 1.1.42026-03-27
CVE-2026-22743 [HIGH] CWE-89 CVE-2026-22743: Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpr
Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited Cypher property accessor (node.`metadata.`) after strip
nvd
CVE-2026-59279P3HIGHCVSS 7.5v2.0.02026-08-21
CVE-2026-59279 [HIGH] CWE-770 CVE-2026-59279: The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on t
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimat
nvd
CVE-2026-41863P3MEDIUMCVSS 6.5≥ 1.1.0, ≤ 1.1.x2026-05-25
CVE-2026-41863 [MEDIUM] CWE-22 CVE-2026-41863: Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.res
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Affected versions:
Spring AI: 1.1.0 through 1.1.x
cvelistv5nvd
CVE-2026-22744P3HIGHCVSS 7.5≥ 1.0.0, < 1.0.5≥ 1.1.0, < 1.1.42026-03-27
CVE-2026-22744 [HIGH] CWE-74 CVE-2026-22744: In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
nvd
CVE-2026-47852P3HIGHCVSS 7.5v2.0.0≥ 1.1.0, ≤ 1.1.8+1 more2026-08-27
CVE-2026-47852 [HIGH] CWE-377 CVE-2026-47852: A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malici
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
nvd
CVE-2026-47851P3HIGHCVSS 7.5v2.0.0≥ 1.1.0, ≤ 1.1.8+1 more2026-08-27
CVE-2026-47851 [HIGH] CWE-674 CVE-2026-47851: Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in t
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
nvd
CVE-2026-59294P3MEDIUMCVSS 6.5v2.0.0≥ 1.1.0, ≤ 1.1.8+1 more2026-08-27
CVE-2026-59294 [MEDIUM] CWE-22 CVE-2026-59294: ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbat
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.9 and earlier
nvd
CVE-2026-59318P3MEDIUMCVSS 6.5v2.0.0≥ 1.1.0, ≤ 1.1.8+1 more2026-08-21
CVE-2026-59318 [MEDIUM] CWE-863 CVE-2026-59318: In Spring AI's tool calling support, the per-request tool list is advertised to the model as a bound
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation.
Affected versions:
Spring AI: 2.0.0
Spring
nvd
CVE-2026-40980P4MEDIUMCVSS 6.5≥ 1.0.0, < 1.0.6≥ 1.1.0, < 1.1.52026-04-28
CVE-2026-40980 [MEDIUM] CWE-400 CVE-2026-40980: In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amoun
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`.
Affected versions:
Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
nvd
CVE-2026-40979P4MEDIUMCVSS 6.1≥ 1.0.0, < 1.0.6≥ 1.1.0, < 1.1.52026-04-28
CVE-2026-40979 [MEDIUM] CWE-377 CVE-2026-40979: In Spring AI, having access to a shared environment can expose the ONNX model used by the applicatio
In Spring AI, having access to a shared environment can expose the ONNX model used by the application.
Affected versions:
Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
nvd
CVE-2026-59319P4MEDIUMCVSS 4.3v2.0.02026-08-27
CVE-2026-59319 [MEDIUM] CWE-943 CVE-2026-59319: RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-suppli
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs. An application that passes user-controlled values to findByMetadata() on a tag-typed metadata fie
nvd
CVE-2026-59308P4MEDIUMCVSS 4.2v2.0.02026-08-21
CVE-2026-59308 [MEDIUM] CWE-668 CVE-2026-59308: In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between dif
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.
Affected versions:
Spring AI: 2.0.0
nvd