CVE-2026-47835

Updated on 15 Jun 2026

Severity

8.6 High severity

Details

CVSS score
8.6
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Overview

About vulnerability

[SVG Image](#description)Description

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB.

[SVG Image](#affected-spring-products-and-versions)Affected Spring Products and Versions

Spring AI:

  • 1.0.0 - 1.0.x
  • 1.1.0 - 1.1.x

Affected components:

  • spring-ai-elasticsearch-store
  • spring-ai-opensearch-store
  • spring-ai-gemfire-store

[SVG Image](#mitigation)Mitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s) Fix version Availability
1.0.x 1.0.9 OSS
1.1.x 1.1.8 OSS

No further mitigation steps are necessary.

[SVG Image](#credit)Credit

The issue was reported responsibly by Nitro Cao (@NitroCao) from Alibaba Cloud.

[SVG Image](#references)References

  • <https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L&version=3.1>

Details

Affected product:
Spring
Affected packages:
spring-ai-starter-model-transformers @ 1.0.9 (+151 more)