Back to overview

CVE-2026-47835

HIGH
8.6
CVSS 3.1
Description
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).

Metadata

CVE ID
CVE-2026-47835
State
PUBLISHED
Assigner
vmware
Reserved
2026-05-20 10:00 UTC
Published
2026-06-15 18:54 UTC
Last updated
2026-06-15 20:06 UTC
Primary CWE
CWE-943
CWE-943: Improper Neutralization of Special Elements in Data…
Vendor / Product
Spring / Spring AI
Sources
cve.org  ·  NVD

Severity & Metrics

8.6 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Spring Spring AI 1.0.0 < 1.0.9, 1.1.0 < 1.1.8
Weakness (CWE)
CWESourceDescription
CWE-943 cna CWE-943: Improper Neutralization of Special Elements in Data Query Logic
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.6 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Back to overview