CVE-2026-47835
Last modified
CVE-2026-47835 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Ai | >= 1.0.0, < 1.0.9 |
| Vmware | Spring Ai | >= 1.1.0, < 1.1.8 |
References
- https://spring.io/security/cve-2026-47835Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47835?
How severe is CVE-2026-47835?
How do I fix CVE-2026-47835?
Are you affected by CVE-2026-47835?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
