Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring AI — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Spring AI, with AI-generated Chinese analysis, references, and POCs.

This page documents common vulnerabilities affecting Spring AI, an artificial intelligence integration framework built on the Spring ecosystem. It aggregates known security weaknesses, configuration errors, and dependency issues specifically impacting Spring AI applications and their underlying components. The dataset covers vulnerabilities discovered and reported from 2023 through the present, reflecting the rapid evolution of AI integration features within the Spring framework. Readers can use this resource to track vendor advisories related to Spring AI updates, understand the mechanics of specific weakness classes such as injection flaws or unsafe deserialization in AI contexts, and look up a product's vulnerability history to assess risk exposure over time. By centralizing this information, the page aims to provide developers and security teams with a clear overview of the threat landscape for Spring AI. It facilitates informed decision-making regarding patching strategies and secure configuration practices. The content is strictly informational, focusing on technical details and historical records rather than promotional material. Users are encouraged to cross-reference this data with official Spring IO security advisories for the most current mitigation guidance. This comprehensive view supports proactive security management for applications leveraging Spring AI capabilities, ensuring that potential risks are identified and addressed promptly.

Vendor: VMware

CVE IDTitleCVSSSeverityPublished
CVE-2026-47835 Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores CWE-943 8.6 High2026-06-15
CVE-2026-41863 LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API CWE-22 6.5 Medium2026-05-25
CVE-2026-41713 Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor CWE-1336 8.2 High2026-05-12
CVE-2026-41712 ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage 7.5 High2026-05-12
CVE-2026-41705 VMware Spring AI 安全漏洞 CWE-917 8.6 High2026-05-09
CVE-2026-40980 VMware Spring AI 资源管理错误漏洞 CWE-400 6.5 Medium2026-04-28
CVE-2026-40979 VMware Spring AI 安全漏洞 CWE-377 6.1 Medium2026-04-28
CVE-2026-40978 VMware Spring AI SQL注入漏洞 CWE-89 8.8 High2026-04-28
CVE-2026-40966 VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration CWE-284 5.9 Medium2026-04-28
CVE-2026-40967 VMware Spring AI 代码注入漏洞 CWE-94 8.6 High2026-04-28
CVE-2026-22744 VMware Spring AI 安全漏洞 7.5 High2026-03-27
CVE-2026-22743 Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore 7.5 High2026-03-27
CVE-2026-22742 Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching 8.6 High2026-03-27
CVE-2026-22738 SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution 9.8 Critical2026-03-27
CVE-2026-22729 CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter 8.6 High2026-03-18
CVE-2026-22730 CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter 8.8 High2026-03-18

All 16 known CVE vulnerabilities affecting Spring AI with full Chinese analysis, references, and POCs where available.