Uncontrolled Recursion in Spring AI - CVE-2026-47851
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unbounded recursion in the PDF Document Reader outline tree processing when analyzing a PDF with a deeply nested or cyclic table of contents. A remote attacker can supply a crafted PDF to cause a denial of service.
The issue can trigger a StackOverflowError in the ingestion thread.