Spring Ai
Vendor:
First CVE: Mar 18, 2026 · Active for under a year
16
Total CVEs
More Total CVEs than 92% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spring Ai over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2026
4 months ago
Most Recent CVE
Jun 15, 2026
39 days ago
CVE Severity & Scoring
Spring Ai16 CVEs
25%
69%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (31.3%)
High0 (0.0%)
None11 (68.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22738CRITICAL In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to exec | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-41705HIGH Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs.
Spring AI 1.0.x: affected from 1.0.0 through | May 9, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-40967HIGH In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, key | Apr 28, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-22730HIGH A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. | Mar 18, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-41713HIGH A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user- | May 12, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-40978HIGH SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs.
Affected versions:
Spring AI: 1.0.0 - | Apr 28, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-22729HIGH A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expre | Mar 18, 2026 | 8.6 | 33 | NO | NO |
CVE-2026-41712HIGH Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users. | May 12, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-22742HIGH Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-su | Mar 27, 2026 | 8.6 | 31 | NO | NO |
CVE-2026-47835HIGH In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: sp | Jun 15, 2026 | 7.5 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Spring Ai
Top CWEs
Versions
No cataloged versions.