方法在根据调用方提供的元数据值构建 RediSearch 标签和文本查询时,未对输入应用 进行转义处理,而同类的 、 和 方法均对输入进行了转义。如果应用程序将用户可控的值传递给标签类型元数据字段的 ,攻击者便可注入 RediSearch 语法(例如 ),从而跳出标签子句,导致匹配索引中所有会话中的所有已索引聊天消息。 Spring AI 2.0.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59270 | 9.4 CRITICAL | Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN o |
| CVE-2026-59324 | 8.2 HIGH | fluxTransform shared RequestMessageHolder causes cross-message header leakage under async |
| CVE-2026-47877 | 8.2 HIGH | Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scri |
| CVE-2026-59316 | 8.2 HIGH | Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XS |
| CVE-2026-59307 | 8.0 HIGH | Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but |
| CVE-2026-47879 | 7.7 HIGH | Spring Cloud Gateway SSRF and native file access with gRPC |
| CVE-2026-47849 | 7.1 HIGH | Spring Data REST allows mutation of identifier and version properties via JSON Patch |
| CVE-2026-59311 | 6.8 MEDIUM | Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation |
| CVE-2026-59272 | 6.8 MEDIUM | Log4j2 AmqpAppender disables TLS hostname verification by default |
| CVE-2026-59293 | 6.6 MEDIUM | SMB minimum protocol dialect defaults to SMB1 |
| CVE-2026-59275 | 6.6 MEDIUM | Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers Sta |
| CVE-2026-59284 | 6.6 MEDIUM | Spring Cloud Commons no allow list for writable env actuator endpoint |
| CVE-2026-59317 | 6.5 MEDIUM | In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFact |
| CVE-2026-59274 | 6.5 MEDIUM | Unbounded decompression in UnZipTransformer enables zip-bomb DoS |
| CVE-2026-59278 | 6.5 MEDIUM | In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types |
| CVE-2026-59320 | 6.5 MEDIUM | In Spring AMQP the link credit never replenished on listener exception path |
| CVE-2026-47864 | 6.4 MEDIUM | Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution |
| CVE-2026-59322 | 6.3 MEDIUM | EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders |
| CVE-2026-47881 | 5.9 MEDIUM | Denial of Service in Spring Batch FlatFileItemReader via Malformed Input File |
| CVE-2026-59276 | 5.9 MEDIUM | Timing Attack via Non-Constant-Time Comparison of Sensitive Values |
Showing top 20 of 64 CVEs. View all on vendor page → →
No comments yet