Vmware
Vmware Spring AI: vulnerabilidades y CVE
Vmware Spring AI tiene 23 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses23
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59319 | Media (4.3) | 0.30% | — | 27 ago 2026 | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same… |
| CVE-2026-59294 | Media (6.5) | 0.36% | — | 27 ago 2026 | ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder,… |
| CVE-2026-47852 | Alta (7.5) | 0.35% | — | 27 ago 2026 | A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 |
| CVE-2026-47851 | Alta (7.5) | 0.46% | — | 27 ago 2026 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9 |
| CVE-2026-59318 | Crítica (9.8) | 0.25% | — | 21 ago 2026 | In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made… |
| CVE-2026-59308 | Media (4.3) | 0.22% | — | 21 ago 2026 | In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring… |
| CVE-2026-59279 | Alta (7.5) | 0.55% | — | 21 ago 2026 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote… |
| CVE-2026-47835 | Alta (7.5) | 0.42% | — | 15 jun 2026 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store,… |
| CVE-2026-41863 | Media (6.5) | 0.41% | — | 25 may 2026 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target… |
| CVE-2026-41713 | Alta (8.2) | 0.35% | — | 12 may 2026 | A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to… |
| CVE-2026-41712 | Alta (7.5) | 0.41% | — | 12 may 2026 | Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. |
| CVE-2026-41705 | Alta (8.6) | 0.39% | — | 9 may 2026 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or… |
| CVE-2026-40980 | Media (6.5) | 0.42% | — | 28 abr 2026 | In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6),… |
| CVE-2026-40979 | Media (6.1) | 0.15% | — | 28 abr 2026 | In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) |
| CVE-2026-40978 | Alta (8.8) | 0.44% | — | 28 abr 2026 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4… |
| CVE-2026-40966 | Media (5.9) | 0.37% | — | 28 abr 2026 | In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only… |
| CVE-2026-40967 | Alta (8.6) | 0.39% | — | 28 abr 2026 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped,… |
| CVE-2026-22744 | Alta (7.5) | 0.25% | — | 27 mar 2026 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG… |
| CVE-2026-22743 | Alta (7.5) | 0.25% | — | 27 mar 2026 | Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in… |
| CVE-2026-22742 | Alta (8.6) | 0.35% | — | 27 mar 2026 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient… |
| CVE-2026-22738 | Crítica (9.8) | 1.1% | — | 27 mar 2026 | In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications… |
| CVE-2026-22730 | Alta (8.8) | 0.52% | — | 18 mar 2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to… |
| CVE-2026-22729 | Alta (8.6) | 0.53% | — | 18 mar 2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.