Critical Spring AI Flaws Expose Databases to SQL and JSONPath Injection
ID: 456780e5-29bc-50af-abb2-19c3e4134deb
STIX ID: report--456780e5-29bc-50af-abb2-19c3e4134deb
Feed Name: securityonline.info
Threat Score
**Advisory:** Two high-severity vulnerabilities (CVE-2026-22729, CVE-2026-22730) in Spring AI allow JSONPath injection and MariaDB SQL injection, enabling attackers to bypass metadata-based access controls and potentially access, modify, or delete sensitive data; users should upgrade to patched versions (1.0.4 / 1.1.3) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
