Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sharlong Wen

#16073of 55,137
17.4Total CVSS
Vulnerabilities · 2
High
2
PT-2026-35667
8.6
2026-04-28
Vmware · Spring Ai · CVE-2026-40967
**Name of the Vulnerable Software and Affected Versions** Spring AI versions 1.0.0 through 1.0.5 Spring AI versions 1.1.0 through 1.1.4 **Description** Various `FilterExpressionConverter` implementations fail to properly escape keys and values when translating filter expression objects into specific vector store query languages. This improper escaping allows for query injection, which can enable attackers to alter vector store queries, potentially leading to data exposure and tampering. **Recommendations** Update versions 1.0.0 through 1.0.5 to 1.0.6. Update versions 1.1.0 through 1.1.4 to 1.1.5.
PT-2026-35687
8.8
2026-04-28
Vmware · Spring Ai · CVE-2026-40978
**Name of the Vulnerable Software and Affected Versions** Spring AI versions 1.0.0 through 1.0.5 Spring AI versions 1.1.0 through 1.1.4 **Description** An issue in `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries by using crafted document IDs. **Recommendations** Update versions 1.0.0 through 1.0.5 to version 1.0.6. Update versions 1.1.0 through 1.1.4 to version 1.1.5.