Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-47835

HIGH NVD
CVSS Score 8.6
Severity HIGH
Published Jun 15, 2026
Vendor unknown

Description

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).

References