18 Total CVEs
10 AI Analyzed
0 CISA KEV
2 Critical
All Vendors
Showing 1-18 of 18 CVEs
CVE-2026-47835
Analyzed
8.6
Spring Spring AI Vector Stores

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire Vec...

2026-06-16
CVE-2026-47825
Analyzed
8.6
Spring Cloud Gateway Server

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios

2026-06-16
CVE-2026-41862
Analyzed
8.8
Spring Spring Statemachine

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforci...

2026-06-24
CVE-2026-41705
8.6
Spring Multiple Products

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs

2026-05-09
CVE-2026-41700
Analyzed
8.1
Spring GraphQL

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking

2026-06-14
CVE-2026-41699
Analyzed
8.1
Spring Spring for GraphQL

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries

2026-06-14
CVE-2026-40999
Analyzed
8.6
Spring Spring WS

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceM...

2026-06-11
CVE-2026-40998
Analyzed
8.2
Spring Web Services

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the J...

2026-06-12
CVE-2026-40994
Analyzed
8.2
Spring Web Services

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement o...

2026-06-12
CVE-2026-40978
8.8
Spring Multiple Products

SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs

2026-04-29
CVE-2026-22738
Analyzed
9.8
Spring Spring AI

Spring AI versions prior to 1.0.5 and 1.1.4 are vulnerable to SpEL injection in SimpleVectorStore when user-supplied input is used as a filter express...

2026-03-27
CVE-2026-22733
8.2
Spring Multiple Products

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...

2026-03-20
CVE-2026-22732
Analyzed
9.1
Spring Spring Security

Spring Security may fail to write HTTP response headers in certain servlet applications. This failure can bypass critical security protections like HS...

2026-03-20
CVE-2026-22731
8.2
Spring Multiple Products

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authen...

2026-03-20
CVE-2026-22730
8.8
Spring Multiple Products

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and e...

2026-03-18
CVE-2026-22729
8.6
Spring Multiple Products

A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access control...

2026-03-18
CVE-2025-41249
7.5
Spring Multiple Products

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized supe...

2025-09-16
CVE-2025-41248
7.5
Spring Multiple Products

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super...

2025-09-16