logo

Injection Flaws (CVE-2026-40967 & 40978) Hit Spring AI Vector Stores

ID: 46a21811-67e6-5383-81b2-c5e1a29adc1b

STIX ID: report--46a21811-67e6-5383-81b2-c5e1a29adc1b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Two high-severity vulnerabilities were disclosed in Spring AI: CVE-2026-40967 (improper escaping in FilterExpression converters enabling query manipulation) and CVE-2026-40978 (SQL injection in CosmosDBVectorStore.doDelete allowing arbitrary SQL via crafted document IDs). Both affect Spring AI versions 1.0.0–1.0.x and 1.1.0–1.1.x; maintainers recommend upgrading to 1.0.6 or 1.1.5 to mitigate the issues. Exploitation requires using the affected VectorStore implementations and allowing user-supplied input to reach vulnerable parameters without validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.