All 6 CVE vulnerabilities found in Spring AI, with AI-generated Chinese analysis, references, and POCs.
Vendor: VMware
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2026-22744 | VMware Spring AI 安全漏洞 | 7.5 | High | 2026-03-27 |
| CVE-2026-22743 | Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore | 7.5 | High | 2026-03-27 |
| CVE-2026-22742 | Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching | 8.6 | High | 2026-03-27 |
| CVE-2026-22738 | SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution | 9.8 | Critical | 2026-03-27 |
| CVE-2026-22729 | CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter | 8.6 | High | 2026-03-18 |
| CVE-2026-22730 | CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter | 8.8 | High | 2026-03-18 |
All 6 known CVE vulnerabilities affecting Spring AI with full Chinese analysis, references, and POCs where available.