CVE-2026-22738
March 27, 2026
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected.
This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Affected Packages
https://github.com/spring-projects/spring-ai.git (GITHUB):
Affected version(s) >=v1.1.0 <v1.1.4Fix Suggestion:
Update to version v1.1.4https://github.com/spring-projects/spring-ai.git (GITHUB):
Affected version(s) >=v0.8.0 <v1.0.5Fix Suggestion:
Update to version v1.0.5https://github.com/spring-projects/spring-ai.git (GITHUB):
Affected version(s) >=v0.8.0 <v1.0.5Fix Suggestion:
Update to version v1.0.5https://github.com/spring-projects/spring-ai.git (GITHUB):
Affected version(s) >=v0.8.0 <v1.0.5Fix Suggestion:
Update to version v1.0.5https://github.com/spring-projects/spring-ai.git (GITHUB):
Affected version(s) >=v1.1.0 <v1.1.4Fix Suggestion:
Update to version v1.1.4org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-vector-store (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4Related Resources (6)
Do you need more information?
Contact UsCVSS v3
Base Score:
9.8
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
EPSS
Base Score:
0.07