In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store.
Affected versions:
Spring AI 1.0.0 through 1.0.x (fix 1.0.9).
Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-47835 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jun 2026, 16:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* | |
| References | () https://spring.io/security/cve-2026-47835 - Vendor Advisory | |
| First Time |
Vmware spring Ai
Vmware |
15 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-15 20:16
Updated : 2026-06-17 16:30
NVD link : CVE-2026-47835
Mitre link : CVE-2026-47835
CVE.ORG link : CVE-2026-47835
JSON object : View
Products Affected
vmware
- spring_ai
CWE
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
