CVE-2026-22742Disclosure(vmware / spring_ai)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-27); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-03-27: 4Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-06: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 4Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 103-2703-2803-3004-0104-06
Signal classification2 categories
Disclosure
675.0%
General
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-274
Disclosure4
2026-03-281
Disclosure1
2026-03-301
Disclosure1
2026-04-011
General1
2026-04-061
General1
Full discourse8 posts
  • V4bel@v4bel
    General

    Here are some Spring vulns (AI slops) I found while casually testing my AI auditing pipeline: CVE-2026-22738: Spring AI SimpleVectorStore SpEL Injection RCE CVE-2026-22742: Spring AI Bedrock SSRF via Unvalidated Media URL CVE-2026-22744: Spring AI RedisVectorStore TAG Filter Injection CVE-2026-22739: Spring Cloud Config Server Profile Path Traversal & SSRF CVE-2026-... Just RCE. Nothing technically impressive. Took me two days 😅

    Post summary

    The author casually reports discovering several Spring AI–related CVEs with basic vulnerability types, but offers no PoC, exploit, patch information, or evidence of real‑world use.

    04046255.0K
    1.5K followersView on X
  • ソリトンシステムズ 公式@soliton_jp
    Disclosure

    LLM連携基盤「Spring AI」にもSSRFの脆弱性が確認されています(CVE-2026-22742)。ユーザー指定URLの検証不備により、内部ネットワークへのアクセスが誘発される恐れがあります。 https://www.security-next.com/182645 #企業公式相互フォロー #SSRF

    Post summary

    The post announces the discovery of a Server‑Side Request Forgery vulnerability (CVE-2026-22742) in the Spring AI LLM integration platform, highlighting a user‑specified URL validation flaw that could allow internal network access.

    000110254
    5.7K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High #SSRF & Injection vulnerabilities in #SpringAI. CVE-2026-22742, CVE-2026-22743, CVE-2026-22744 CVSS: 8.6. These CVEs can lead to unintended server requests and database access. #Patch #Patch #Patch

    Post summary

    The post discloses high‑severity SSRF‑and‑injection CVEs for SpringAI (CVE‑2026‑22742/22743/22744) with CVSS 8.6, warning of unintended server requests and database access, but provides no PoC, exploit code, or specific patch details.

    01001224
    7.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-22744 ❗ CVE-2026-22742 ❗ CVE-2026-22738 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-3/ https://t.co/RfKNkkZsdP

    Post summary

    The tweet lists three Spring product CVEs and points to a CERT page for more information, but it provides no details on the vulnerability, PoC, exploit, or mitigations.

    00010161
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22742 Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that i… https://www.cve.org/CVERecord?id=CVE-2026-22742

    Post summary

    A new SSRF vulnerability (CVE-2026-22742) has been identified in Spring AI's spring-ai-bedrock-converse, affecting BedrockProxyChatModel for multimodal messages; no PoC, exploit, or mitigation has been disclosed.

    0001083
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22742: HIGH] A Server-Side Request Forgery (SSRF) vulnerability in Spring AI's spring-ai-bedrock-converse can trigger unintended HTTP requests to internal/external destinations. Update to versions ...#cve,CVE-2026-22742,#cybersecurity https://cvefind.com/CVE-2026-22742

    Post summary

    The post discloses a high‑severity SSRF vulnerability in Spring AI’s spring‑ai‑bedrock‑converse and indicates that updates to newer versions are available to remediate the issue.

    0000138
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22742 - High Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied m... https://www.thehackerwire.com/vulnerability/CVE-2026-22742/ https://t.co/5KjDj41qeF

    Post summary

    The tweet announces CVE-2026-22742, a high‑severity SSRF vulnerability in Spring AI's spring‑ai-bedrock-converse component, specifically affecting BedrockProxyChatModel in multimodal message processing.

    0000039
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22742 - Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching Intel Report: https://ift.tt/4fNM0pm

    Post summary

    The announcement introduces CVE‑2026‑22742, a server‑side request forgery in BedrockProxyChatModel due to unvalidated media URL fetching, with a link to an intel report but no PoC, exploit, or patch details.

    0000039
    284 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more