CVE-2026-47835Patch(vmware / spring_ai)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-08-04: 108-04
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • 万人往@CodeShieldLab
    Patch

    给做 RAG / 向量检索的 Java 开发者: 过滤器里,空白字符也是语法边界。 Spring AI 的公开补丁提醒:对象转为查询字符串时,只处理普通空格不够;控制字符与 Unicode 空白也可能被后端赋予语法。 安全不变量:元数据进入解析器后,必须始终只是数据。 CVE-2026-47835|仅分析公开补丁

    Post summary

    The text focuses on Spring AI’s public patch for CVE‑2026‑47835, describing how whitespace handling in query string conversion is a vulnerability, without evidence of exploitation or a PoC.

    0000061
    14 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more