VYPR
Vendor

Spring AI

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-59318MedAug 21, 2026
    risk 0.42cvss 6.5epss

    In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially…

  • CVE-2026-59296MedAug 21, 2026
    risk 0.38cvss 5.9epss

    Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. When such unsafe instrumentation is used, the application becomes vulnerable to…

  • CVE-2026-59308MedAug 21, 2026
    risk 0.27cvss 4.2epss

    In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0