CVE-2026-40967Disclosure(vmware / spring_ai)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch vmware spring_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-28); latest day: 2
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline9 mentions / 4d
01345Mentions · 2026-04-28: 5Mentions · 2026-04-30: 1Mentions · 2026-05-04: 1Mentions · 2026-05-25: 2Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-28: 4Technical Details · 2026-05-25: 104-2804-3005-0405-25
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-285
Disclosure4Patch1
2026-04-301
General1
2026-05-041
General1
2026-05-252
Disclosure2
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    Spring AI discloses two critical injection flaws (CVE-2026-40967 & 40978) in Vector Store implementations. Upgrade to v1.0.6 or v1.1.5 now to prevent data leaks. #SpringAI #VectorStore #CyberSecurity #InfoSec #PatchAlert #CVE #AISecurity https://securityonline.info/spring-ai-vector-store-injection-vulnerabilities-patch-guide/ https://t.co/yUTaAPgzWm

    Post summary

    Spring AI announces two injection vulnerabilities in Vector Store and recommends upgrading to v1.0.6 or v1.1.5 to mitigate data leakage risks.

    01031456
    12.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    [1] Spring Security Advisory - CVE-2026-40967: [2] Tenable CVE Record - CVE-2026-40967: [3] Tenable Research Advisory - Spring AI SQL Injection in PgVectorStore and friends (TRA-2026-36):…

    Post summary

    The excerpt cites a Spring Security advisory and Tenable records for CVE‑2026‑40967, indicating the vulnerability has been officially disclosed but no PoC, exploit, active use, or mitigation details are provided.

    1000043
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On April 27, 2026, the Spring Security team disclosed CVE-2026-40967, a HIGH severity vulnerability (CVSS 8.6) in Spring AI's vector store integration layer. The flaw exists in multiple FilterExpressionConverter implementations that accept filter expression objects and…

    Post summary

    The post announces the disclosure of CVE-2026-40967, a high‑severity vulnerability in Spring AI’s vector store integration, affecting multiple FilterExpressionConverter implementations. No proof‑of‑concept, exploitation code, active attacks, or mitigation details are mentioned.

    1000048
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40967 In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In seve… https://www.cve.org/CVERecord?id=CVE-2026-40967

    Post summary

    CVE-2026-40967 reveals a flaw in Spring AI’s handling of filter expressions that could affect vector store query translation, constituting a disclosed vulnerability.

    00010178
    57.3K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High Query Injection in #SpringAI. #CVE-2026-40967 CVSS: 8.6. Improper escaping in FilterExpressionConverter may let attackers alter vector store queries, leading to data exposure and tampering! #Patch #Patch #Patch

    Post summary

    The tweet alerts to a high‑severity query injection flaw (CVE‑2026‑40967) in SpringAI that could expose or tamper with data, but no proof of concept, exploit code, or active exploitation is mentioned.

    01000179
    7.2K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-40967: Spring AI Query Escaping Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04fgTXY0

    Post summary

    The text references CVE-2026-40967 in an article title but provides no substantive details about the vulnerability, exploits, patches, or activity.

    0000034
    29 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Spring ❗ CVE-2026-40978 ❗ CVE-2026-40967 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-spring-6/ https://t.co/PnhEEKb0Yg

    Post summary

    The tweet lists two Spring CVEs and points to a source for further reading, providing no technical, exploitation, or patch details.

    0000076
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40967 In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In seve… https://www.cve.org/CVERecord?id=CVE-2026-40967 ----- Traducción: CVE-2026-40967 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑40967, detailing how Spring AI’s FilterExpressionConverter processes filter expressions, but provides no evidence of exploitation, patches, or debunking.

    0000032
    73 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40967 Query Injection in Spring AI FilterExpressionConverter Implementa... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40967 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    This tweet announces a new query injection vulnerability in Spring AI's FilterExpressionConverter, links to a vulnerability details page, and provides limited technical detail without mention of exploits, patches, or active usage.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more