Spring AI
4 known vulnerabilities in Spring AI, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-59319 CVSS 4.3 medium RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying…
- CVE-2026-59294 CVSS 6.5 medium ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators…
- CVE-2026-47852 CVSS 7.5 high A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0…
- CVE-2026-47851 CVSS 7.5 high Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0…