CVE-2026-59319
- EPSS 0.22%
- Veröffentlicht 27.08.2026 18:04:46
- Zuletzt bearbeitet 31.08.2026 17:18:49
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inpu...
CVE-2026-59294
- EPSS 0.25%
- Veröffentlicht 27.08.2026 17:57:52
- Zuletzt bearbeitet 31.08.2026 23:24:18
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloa...
CVE-2026-47852
- EPSS 0.2%
- Veröffentlicht 26.08.2026 23:28:42
- Zuletzt bearbeitet 04.09.2026 20:08:46
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
CVE-2026-47851
- EPSS 0.26%
- Veröffentlicht 26.08.2026 23:28:41
- Zuletzt bearbeitet 04.09.2026 20:08:06
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
CVE-2026-59318
- EPSS 0.17%
- Veröffentlicht 21.08.2026 12:16:30
- Zuletzt bearbeitet 16.09.2026 14:01:40
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request coul...
CVE-2026-59308
- EPSS 0.16%
- Veröffentlicht 21.08.2026 12:16:30
- Zuletzt bearbeitet 16.09.2026 14:06:31
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
CVE-2026-59279
- EPSS 0.39%
- Veröffentlicht 21.08.2026 12:16:30
- Zuletzt bearbeitet 16.09.2026 14:06:48
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to ...
CVE-2026-41863
- EPSS 0.4%
- Veröffentlicht 25.05.2026 05:45:37
- Zuletzt bearbeitet 23.07.2026 17:10:00
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted direct...
CVE-2026-41713
- EPSS 0.22%
- Veröffentlicht 12.05.2026 10:17:39
- Zuletzt bearbeitet 12.05.2026 19:25:06
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior ...
CVE-2026-41712
- EPSS 0.26%
- Veröffentlicht 12.05.2026 10:17:36
- Zuletzt bearbeitet 12.05.2026 19:26:04
Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.