SB20260828161 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI



SB20260828161 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI

Published: August 28, 2026

Security Bulletin ID SB20260828161
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-47835)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary queries.

The vulnerability exists due to improper neutralization of special elements in spring ai vector store metadata filtering in Elasticsearch, OpenSearch, and GemFire vector stores when processing metadata filter input. A remote attacker can supply special characters in crafted metadata filters to execute arbitrary queries.


Remediation

Install update from vendor's website.