Input validation error in Spring AI - CVE-2026-40966
Published: April 27, 2026
Spring AI
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in VectorStoreChatMemoryAdvisor when processing user-supplied conversationId values. A remote attacker can inject crafted filter logic to disclose sensitive information.
Only applications that pass user-supplied input as a conversationId are vulnerable.