logo

Critical 9.8 CVSS SpEL Injection and SSRF Flaws Hit Spring AI Framework

ID: 89a29334-d139-52e5-92eb-8ef9592a2e41

STIX ID: report--89a29334-d139-52e5-92eb-8ef9592a2e41

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

This advisory describes three vulnerabilities in Spring AI (versions 1.0.0–1.1.x): a critical SpEL injection allowing unauthenticated RCE (CVE-2026-22738, CVSS 9.8), an SSRF in media URL handling (CVE-2026-22742, CVSS 8.6), and a Cypher injection against Neo4j filters (CVE-2026-22743, CVSS 7.5); maintainers should upgrade to 1.0.5 or 1.1.4 to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.