CVE-2026-22730 is a critical SQL injection vulnerability (CVSS 8.8 HIGH) in Spring AI's MariaDBFilterExpressionConverter, caused by missing input sanitization. This flaw allows attackers with low privileges to bypass metadata-based access controls and execute arbitrary SQL commands over the network, leading to high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, it is on the Hot List and has generated significant community discussion, indicating active monitoring and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.3CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.