PT-2026-35667 · Spring · Spring Ai

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-40967

CVSS v3.1

8.6

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query.
Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-40967

Affected Products

Spring Ai