Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI - CVE-2026-47835

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI - CVE-2026-47835

Published: August 28, 2026


Vulnerability identifier: #VU146194
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47835
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary queries.

The vulnerability exists due to improper neutralization of special elements in spring ai vector store metadata filtering in Elasticsearch, OpenSearch, and GemFire vector stores when processing metadata filter input. A remote attacker can supply special characters in crafted metadata filters to execute arbitrary queries.


Affected software

Spring AI

How to mitigate CVE-2026-47835

Install security update from vendor's website.

Spring AI - addressed in versions 1.0.9, 1.1.8

External References

Related Security Bulletins