VYPR

Spring AI

by Spring AI

CVEs (14)

  • CVE-2026-59354CriAug 27, 2026
    risk 0.55cvss 9.6epss 0.00

    In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An…

  • CVE-2026-47885HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28

  • CVE-2026-47852HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

  • CVE-2026-47851HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

  • CVE-2026-59279HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded…

  • CVE-2026-40998HigJun 11, 2026
    risk 0.46cvss 8.2epss 0.00

    Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath…

  • CVE-2026-59275MedAug 27, 2026
    risk 0.43cvss 6.6epss 0.00

    A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18…

  • CVE-2026-59318MedAug 21, 2026
    risk 0.42cvss 6.5epss 0.00

    In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially…

  • CVE-2026-59294MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI…

  • CVE-2026-59271MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

  • CVE-2026-47894MedAug 27, 2026
    risk 0.32cvss 4.9epss 0.00

    Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

  • CVE-2026-41710MedJun 9, 2026
    risk 0.31cvss 5.9epss 0.00

    An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects any further updates, causing all later stateful retries and circuit breakers in…

  • CVE-2026-59319MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs. An application that…

  • CVE-2026-59308MedAug 21, 2026
    risk 0.27cvss 4.2epss 0.00

    In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0