Spring AI
Spring- Software type
- —
- Catalog vulnerabilities
- 18
Severity across 18 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 18 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, Spring AI has 8 security vulnerabilities published in the last 90 days. Of these, 4 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Spring AI and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-59319RediSearch Tag Injection in RedisChatMemoryRepository Allows Cross-Conversation Data Exposure | Exploitation statusNot known exploited | FixNot confirmed | Published08/27/2026 | SeverityMedium |
CVE-2026-59294Arbitrary File Write via Path Traversal in ResourceCacheService | Exploitation statusNot known exploited | FixYes | Published08/27/2026 | SeverityMedium |
CVE-2026-47852Predictable cache directory location allows local ONNX model substitution in Spring AI | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityHigh |
CVE-2026-47851Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityHigh |
CVE-2026-59318DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via Prompt Injection | Exploitation statusNot known exploited | FixYes | Published08/21/2026 | SeverityMedium |
CVE-2026-59308Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation | Exploitation statusNot known exploited | FixNot confirmed | Published08/21/2026 | SeverityMedium |
CVE-2026-59279Unbounded persistent session allocation via repeated initialize requests | Exploitation statusNot known exploited | FixNot confirmed | Published08/21/2026 | SeverityHigh |
CVE-2026-47835Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores | Exploitation statusNot known exploited | FixYes | Published06/15/2026 | SeverityHigh |
CVE-2026-41863LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API | Exploitation statusNot known exploited | FixYes | Published05/25/2026 | SeverityMedium |
CVE-2026-41705CVE-2026-41705 | Exploitation statusNot known exploited | FixYes | Published05/09/2026 | SeverityHigh |
CVE-2026-40980CVE-2026-40980 | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityMedium |
CVE-2026-40979CVE-2026-40979 | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityMedium |
CVE-2026-40978CVE-2026-40978 | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-40967CVE-2026-40967 | Exploitation statusNot known exploited | FixYes | Published04/28/2026 | SeverityHigh |
CVE-2026-22744CVE-2026-22744 | Exploitation statusNot known exploited | FixYes | Published03/27/2026 | SeverityHigh |
CVE-2026-22743Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore | Exploitation statusNot known exploited | FixYes | Published03/27/2026 | SeverityHigh |
CVE-2026-22742Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching | Exploitation statusNot known exploited | FixYes | Published03/27/2026 | SeverityHigh |
CVE-2026-22738SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution | Exploitation statusNot known exploited | FixYes | Published03/27/2026 | SeverityCritical |