CVE-2026-22744

In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
References
Link Resource
https://spring.io/security/cve-2026-22744 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*

History

02 Jun 2026, 17:16

Type Values Removed Values Added
CWE CWE-74

16 Apr 2026, 20:24

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
First Time Vmware
Vmware spring Ai
References () https://spring.io/security/cve-2026-22744 - () https://spring.io/security/cve-2026-22744 - Vendor Advisory
CWE NVD-CWE-noinfo

27 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 06:16

Updated : 2026-06-02 17:16


NVD link : CVE-2026-22744

Mitre link : CVE-2026-22744

CVE.ORG link : CVE-2026-22744


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
NVD-CWE-noinfo CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')