Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/com.vmware/spring-ai

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-59318 is an authorization vulnerability in Spring AI's tool calling support. The vulnerability arises because the per-request tool list, which is advertised to the model as a boundary, is not fully enforced when dispatching a tool call. This can allow a tool that was not made available to the current request to be invoked, potentially leading to privilege escalation. The issue affects multiple versions of Spring AI, including 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and version 2.0.0.

Join the discussion

CVE-2026-59308 is a medium severity vulnerability in Spring AI version 2.0.0 involving the Semantic Cache feature. The context hash intended to isolate cached responses between different system prompts may allow cached responses to be shared across unrelated contexts, potentially exposing information to the wrong context. The vulnerability has a CVSS score of 4.2, indicating limited confidentiality and integrity impact with no availability impact. No patch or remediation details are provided in the available data.

Join the discussion

CVE-2026-59279 is a high-severity vulnerability in Spring AI version 2.0.0 where the MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not limit the number of sessions retained and does not require client authentication by default. This allows a remote attacker to cause the server to accumulate an unlimited number of sessions, leading to memory exhaustion and denial of service for legitimate clients.

Join the discussion

CVE-2026-41863 is a path traversal vulnerability in Spring AI version 1.1.0. It occurs because the product uses unsanitized, LLM-influenced filenames in Path.resolve before writing files to disk, allowing an attacker with limited privileges to write files outside the intended directory. This could lead to unauthorized file modification or creation in restricted directories. The vulnerability has a medium severity with a CVSS score of 6.5. No official patch or remediation guidance is currently available from the vendor.

Join the discussion

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

Join the discussion

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

Join the discussion

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater.

Join the discussion

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Join the discussion

In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

Join the discussion

CVE-2026-40978 is a high-severity SQL injection vulnerability in the CosmosDBVectorStore component of Spring AI versions 1.0.0 through 1.0.5 and 1.1.0 through 1.1.4. This flaw allows attackers with limited privileges to execute arbitrary SQL commands by leveraging crafted document IDs.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:maven/com.vmware/spring-ai
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses