logo

Critical Spring AI Flaws Expose Databases to SQL and JSONPath Injection

ID: 456780e5-29bc-50af-abb2-19c3e4134deb

STIX ID: report--456780e5-29bc-50af-abb2-19c3e4134deb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

**Advisory:** Two high-severity vulnerabilities (CVE-2026-22729, CVE-2026-22730) in Spring AI allow JSONPath injection and MariaDB SQL injection, enabling attackers to bypass metadata-based access controls and potentially access, modify, or delete sensitive data; users should upgrade to patched versions (1.0.4 / 1.1.3) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.