Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Spring AI — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Spring AI, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the product Spring AI, focusing on Common Weakness Enumeration (CWE) classifications provided by the vendor. It collects detailed records of security flaws affecting this specific artificial intelligence integration framework, covering reported vulnerabilities from initial discovery through to recent updates. By utilizing this centralized repository, users can efficiently track the vendor’s security advisories to stay informed about critical patches and mitigation strategies. Furthermore, the page allows for a deeper understanding of specific weakness classes that have impacted the software, offering context on how these issues manifest within the application’s architecture. Visitors can also look up a product's complete vulnerability history to assess long-term security trends and the effectiveness of previous remediation efforts. This resource serves as a comprehensive reference for developers, security analysts, and system administrators who rely on Spring AI, enabling them to make informed decisions regarding risk management and system hardening without needing to search across multiple fragmented sources. The data is structured to facilitate easy cross-referencing between specific CVE identifiers and their associated technical descriptions, ensuring that users can quickly identify the relevance of each finding to their specific deployment environment.

Vendor: VMware

CVE ID Title CVSS Severity Published
CVE-2026-59318 DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection CWE-863 6.5 Medium 2026-08-21
CVE-2026-59308 Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation CWE-668 4.2 Medium 2026-08-21
CVE-2026-59279 Unbounded persistent session allocation via repeated initialize requests CWE-770 7.5 High 2026-08-21
CVE-2026-47835 Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores CWE-943 8.6 High 2026-06-15
CVE-2026-41863 LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API CWE-22 6.5 Medium 2026-05-25
CVE-2026-41713 Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor CWE-1336 8.2 High 2026-05-12
CVE-2026-41712 ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage 7.5 High 2026-05-12
CVE-2026-41705 VMware Spring AI 安全漏洞 CWE-917 8.6 High 2026-05-09
CVE-2026-40980 VMware Spring AI 资源管理错误漏洞 CWE-400 6.5 Medium 2026-04-28
CVE-2026-40979 VMware Spring AI 安全漏洞 CWE-377 6.1 Medium 2026-04-28
CVE-2026-40978 VMware Spring AI SQL注入漏洞 CWE-89 8.8 High 2026-04-28
CVE-2026-40966 VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration CWE-284 5.9 Medium 2026-04-28
CVE-2026-40967 VMware Spring AI 代码注入漏洞 CWE-94 8.6 High 2026-04-28
CVE-2026-22744 VMware Spring AI 安全漏洞 7.5 High 2026-03-27
CVE-2026-22743 Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore 7.5 High 2026-03-27
CVE-2026-22742 Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching 8.6 High 2026-03-27
CVE-2026-22738 SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution 9.8 Critical 2026-03-27
CVE-2026-22729 CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter 8.6 High 2026-03-18
CVE-2026-22730 CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter 8.8 High 2026-03-18

All 19 known CVE vulnerabilities affecting Spring AI with full Chinese analysis, references, and POCs where available.