pyn3rd[verified]@pyn3rdDisclosure
The tweet announces CVE-2026-22738, a Spring AI SimpleVectorStore vulnerability featuring SpEL injection that allows remote code execution in AI pipelines.
V4bel[verified]@v4belGeneral
The user lists several Spring AI component CVEs with brief impact descriptors, but offers no proof‑of‑concept, exploit code, or patch information.
Nicolas Krassas[verified]@DinosnDisclosure
The blog post discloses CVE‑2026‑22738, describing a Spring AI SpEL injection that can lead from vector search to remote code execution, but does not provide fixes or evidence of current exploitation.
Djalil Ayed[verified]@DjalilAyedExploit
The post announces a TryHackMe room that demonstrates CVE‑2026‑22738, detailing an unauthenticated RCE via SpEL injection in Spring AI’s SimpleVectorStore and providing a link to the PoC.
blueblue@piedpiper1616PoC
The text announces a GitHub repository containing a Proof of Concept for CVE-2026-22738, but provides no details on active exploitation, patches, or false positive status.
Gray Hats@the_yellow_fallPatch
Spring AI announces a critical patch (v1.1.4) that addresses SpEL injection, SSRF, and Cypher injection flaws (CVE-2026-22738) with a CVSS of 9.8, urging users to upgrade immediately.
CERT-PY@CERTpyDisclosure
Three new CVEs affecting Spring products—CVE-2026-22744, CVE-2026-22742, and CVE-2026-22738—have been announced, with additional details available via the provided links.
The Hacker Wire@TheHackerWireDisclosure
A new critical SpEL injection vulnerability in Spring AI's SimpleVectorStore enables arbitrary code execution via user-supplied filter expressions; the post provides no PoC, exploit code, or patch details.