Nicolas Krassas[verified]@DinosnDisclosure
The text announces a newly identified JSONPath injection vulnerability in Spring AI’s PgVectorStore and directs readers to a blog post for further details.
dbugs[verified]@ptdbugsDisclosure
The post announces a new JSONPath injection flaw (CVE-2026-22729) in VMware Spring AI, detailing how authenticated users can inject JSONPath logic to bypass access controls, but it does not mention a PoC, active exploitation, or patch.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The post announces the discovery of two new Java Spring AI vulnerabilities (CVE-2026-22730 and CVE-2026-22729) that involve SQL injection and JSONPath injection, linking to a detailed security report.
Prabhat Kashyap | prabhat.dev[verified]@prabhatdotdevPatch
Spring AI is impacted by two critical CVEs that enable injection attacks to bypass access controls across tenants; users are urged to upgrade immediately to patched releases.
Gray Hats@the_yellow_fallDisclosure
The tweet announces critical Spring AI vulnerabilities (CVE‑2026‑22729 and CVE‑2026‑22730) that enable access control bypass through JSONPath and SQL injection, urging users to apply updates.
/r/netsec@_r_netsecDisclosure
The SecureLayer7 blog post announces a new CVE-2026-22729, describing a JSONPath Injection vulnerability in Spring AI’s PgVectorStore.
CCB Alert@CCBalertPatch
A high-severity CVE-2026-22729 in Spring AI allows authenticated users to bypass access controls; patches 1.0.4 and 1.1.3 are recommended and available.
SecureLayer7@SecureLayer7General
The text consists solely of two URLs to blog posts about CVE-2026-25049 and CVE-2026-22729 (JSONPath injection in Spring AI pgVectorStore), with no additional context, technical details, or actionable information provided in the tweet/post text itself.