CVE-2026-22738Disclosure(vmware / spring_ai)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch vmware spring_ai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.

4.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-917CWE-88

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 9 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-04-03); latest day: 1
  • 15 total mentions across 9 days

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline15 mentions / 9d
01345Mentions · 2026-03-26: 1Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-03: 5Mentions · 2026-04-06: 1Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-03: 2Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-04-03: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-03: 3Technical Details · 2026-04-20: 103-2603-2703-2803-3104-0104-0204-0304-0604-20
Signal classification5 categories
Disclosure
853.3%
General
320.0%
PoC
213.3%
Patch
16.7%
Exploit
16.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-261
Patch1
2026-03-273
Disclosure3
2026-03-281
Disclosure1
2026-03-311
Disclosure1
2026-04-011
General1
2026-04-021
PoC1
2026-04-035
Disclosure1Exploit1General2PoC1
2026-04-061
Disclosure1
2026-04-201
Disclosure1
Full discourse15 posts
  • pyn3rd@pyn3rd
    Disclosure

    #CVE-2026-22738: Spring AI SimpleVectorStore Hit by SpEL Injection — Remote Code Execution Risk in AI Pipelines https://t.co/AJJt44l7qt

    Post summary

    The tweet announces CVE-2026-22738, a Spring AI SimpleVectorStore vulnerability featuring SpEL injection that allows remote code execution in AI pipelines.

    110074265.3K
    15.1K followersView on X
  • V4bel@v4bel
    General

    Here are some Spring vulns (AI slops) I found while casually testing my AI auditing pipeline: CVE-2026-22738: Spring AI SimpleVectorStore SpEL Injection RCE CVE-2026-22742: Spring AI Bedrock SSRF via Unvalidated Media URL CVE-2026-22744: Spring AI RedisVectorStore TAG Filter Injection CVE-2026-22739: Spring Cloud Config Server Profile Path Traversal & SSRF CVE-2026-... Just RCE. Nothing technically impressive. Took me two days 😅

    Post summary

    The user lists several Spring AI component CVEs with brief impact descriptors, but offers no proof‑of‑concept, exploit code, or patch information.

    04046255.0K
    1.5K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - n0n4m3x41/CVE-2026-22738-POC: PoC for CVE-2026-22738 · GitHub - https://github.com/n0n4m3x41/CVE-2026-22738-POC

    Post summary

    The text announces a GitHub repository containing a Proof of Concept for CVE-2026-22738, but provides no details on active exploitation, patches, or false positive status.

    07037224.0K
    5.5K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Spring AI SpEL Injection: From Vector Search to Remote Code Execution (CVE-2026-22738) https://www.resecurity.com/blog/article/spring-ai-spel-injection-from-vector-search-to-remote-code-execution-cve-2026-22738

    Post summary

    The blog post discloses CVE‑2026‑22738, describing a Spring AI SpEL injection that can lead from vector search to remote code execution, but does not provide fixes or evidence of current exploitation.

    020541.8K
    158.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Spring AI patches critical 9.8 CVSS SpEL injection (CVE-2026-22738), SSRF, and Cypher injection flaws. Secure your AI applications—upgrade to 1.1.4 now. #SpringAI #CyberSecurity #InfoSec #RCE #Java #AI #Vulnerability #PatchAlert #SSRF #DevSecOps #Neo4j https://securityonline.info/spring-ai-security-vulnerabilities-rce-ssrf-spel-injection-patch/ https://t.co/LNMPGTRP8O

    Post summary

    Spring AI announces a critical patch (v1.1.4) that addresses SpEL injection, SSRF, and Cypher injection flaws (CVE-2026-22738) with a CVSS of 9.8, urging users to upgrade immediately.

    01062382
    10.9K followersView on X
  • Djalil Ayed@DjalilAyed
    Exploit

    🥝 New room Spring AI: CVE-2026-22738 from @tryhackme 🦊 Exploit CVE-2026-22738: unauthenticated RCE via SpEL injection in Spring AI's SimpleVectorStore. 🐱 Room link: https://tryhackme.com/room/springaicve202622738 #tryhackme https://t.co/q1NfIMW9fX

    Post summary

    The post announces a TryHackMe room that demonstrates CVE‑2026‑22738, detailing an unauthenticated RCE via SpEL injection in Spring AI’s SimpleVectorStore and providing a link to the PoC.

    00031165
    847 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22744 ❗ CVE-2026-22742 ❗ CVE-2026-22738 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-3/ https://t.co/RfKNkkZsdP

    Post summary

    Three new CVEs affecting Spring products—CVE-2026-22744, CVE-2026-22742, and CVE-2026-22738—have been announced, with additional details available via the provided links.

    00010161
    6.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22738 - Critical In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute a... https://www.thehackerwire.com/vulnerability/CVE-2026-22738/ https://t.co/oqGZiF4BQx

    Post summary

    A new critical SpEL injection vulnerability in Spring AI's SimpleVectorStore enables arbitrary code execution via user-supplied filter expressions; the post provides no PoC, exploit code, or patch details.

    0001056
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22738: CRITICAL] Critical SpEL injection vulnerability found in Spring AI's SimpleVectorStore. Attackers may execute arbitrary code by exploiting user-supplied values in filter expression keys. Ver...#cve,CVE-2026-22738,#cybersecurity https://cvefind.com/CVE-2026-22738

    Post summary

    A critical SpEL injection vulnerability (CVE‑2026‑22738) has been disclosed in Spring AI's SimpleVectorStore, enabling attackers to execute arbitrary code through crafted filter expression keys.

    0000148
    617 followersView on X
  • ‘BBWriteups’@bbwriteup
    General

    "TryHackMe | Spring AI: CVE-2026–22738 | WriteUp" by Axoloth #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/h7w/tryhackme-spring-ai-cve-2026-22738-writeup-354db657d620

    Post summary

    The provided text references a WriteUp for CVE-2026-22738 but offers no explicit details on exploitation, mitigations, or technical characteristics.

    0000044
    563 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    PoC

    I just completed Spring AI: CVE-2026-22738 room on TryHackMe! Exploit CVE-2026-22738: unauthenticated RCE via SpEL injection in Spring AI's SimpleVectorStore. https://tryhackme.com/room/springaicve202622738?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet announces a TryHackMe room that demonstrates unauthenticated RCE via SpEL injection in Spring AI, providing a proof of concept for CVE-2026-22738.

    0000027
  • ‘BBWriteups’@bbwriteup
    General

    "Spring AI: CVE-2026–22738 Walkthrough Notes | TryHackMe" by Sle3pyHead ‍ #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@Sle3pyHead/spring-ai-cve-2026-22738-walkthrough-notes-tryhackme-69d286956697

    Post summary

    The text announces a walkthrough article about CVE‑2026‑22738 on TryHackMe, but provides no detailed information about exploits, patches, or the vulnerability itself.

    0000061
    563 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A `Spring AI` vulnerability (CVE-2026-22738) allows SpEL injection via user-supplied filter expression keys, potentially leading to remote code execution. #SpringAI #SpEL #infosec https://www.pulsepatch.io/posts/cve-2026-22738-spring-ai-spel-injection

    Post summary

    The post discloses CVE-2026-22738, detailing a SpEL injection flaw in Spring AI that could enable remote code execution, but offers no PoC, patch, or exploitation evidence.

    0000027
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22738 In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploi… https://www.cve.org/CVERecord?id=CVE-2026-22738

    Post summary

    The post discloses a SpEL injection flaw in Spring AI’s SimpleVectorStore that lets attackers exploit user-supplied filter keys, but it provides no PoC, exploit, active attack evidence, or patch information.

    0000097
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-22738: SpEL Injection via Unescaped Fil... Spring Expression Language meets vector databases - filter keys become RCE goldmines when devs trust user input in Simp... https://zerodaysignal.com/vulnerability/CVE-2026-22738 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts to CVE-2026-22738, a SpEL injection that can turn filter keys into RCE vectors in vector databases, with a link for further details. It provides the vulnerability type but no PoC code or exploitation evidence.

    0000073
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more