TopVuln

High-risk vulnerability digests

CVE-2026-22738

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-03-27 06:16:37
Affected versions
Spring AI 1.0.0 before 1.0.5, 1.1.0 before 1.1.4
Summary
This is a SpEL injection vulnerability in Spring AI's SimpleVectorStore component that occurs when user-supplied values are used as filter expression keys. A remote malicious actor can exploit this flaw to execute arbitrary code on the affected system. Only applications that use SimpleVectorStore and accept user-supplied filter keys are impacted.
Remediation
Update Spring AI to version 1.0.5 or later for the 1.0.x branch, and 1.1.4 or later for the 1.1.x branch. If an immediate update is not possible, restrict untrusted user input to filter expression keys. Disable public access to vulnerable endpoints that use the affected SimpleVectorStore feature.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.