
Here are some Spring vulns (AI slops) I found while casually testing my AI auditing pipeline: CVE-2026-22738: Spring AI SimpleVectorStore SpEL Injection RCE CVE-2026-22742: Spring AI Bedrock SSRF via Unvalidated Media URL CVE-2026-22744: Spring AI RedisVectorStore TAG Filter Injection CVE-2026-22739: Spring Cloud Config Server Profile Path Traversal & SSRF CVE-2026-... Just RCE. Nothing technically impressive. Took me two days 😅
Post summary
The author casually lists several Spring AI-related CVEs, noting their types (RCE, SSRF, injection) but provides no PoC, exploit code, or patch details.




