V4bel[verified]@v4belGeneral
The author casually reports discovering several Spring AI–related CVEs with basic vulnerability types, but offers no PoC, exploit, patch information, or evidence of real‑world use.
ソリトンシステムズ 公式[verified]@soliton_jpDisclosure
The post announces the discovery of a Server‑Side Request Forgery vulnerability (CVE-2026-22742) in the Spring AI LLM integration platform, highlighting a user‑specified URL validation flaw that could allow internal network access.
CCB Alert@CCBalertDisclosure
The post discloses high‑severity SSRF‑and‑injection CVEs for SpringAI (CVE‑2026‑22742/22743/22744) with CVSS 8.6, warning of unintended server requests and database access, but provides no PoC, exploit code, or specific patch details.
CERT-PY@CERTpyGeneral
The tweet lists three Spring product CVEs and points to a CERT page for more information, but it provides no details on the vulnerability, PoC, exploit, or mitigations.
CVE@CVEnewDisclosure
A new SSRF vulnerability (CVE-2026-22742) has been identified in Spring AI's spring-ai-bedrock-converse, affecting BedrockProxyChatModel for multimodal messages; no PoC, exploit, or mitigation has been disclosed.
CVEFind.com@CveFindComDisclosure
The post discloses a high‑severity SSRF vulnerability in Spring AI’s spring‑ai‑bedrock‑converse and indicates that updates to newer versions are available to remediate the issue.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-22742, a high‑severity SSRF vulnerability in Spring AI's spring‑ai-bedrock-converse component, specifically affecting BedrockProxyChatModel in multimodal message processing.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The announcement introduces CVE‑2026‑22742, a server‑side request forgery in BedrockProxyChatModel due to unvalidated media URL fetching, with a link to an intel report but no PoC, exploit, or patch details.