Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.ai/spring-ai-vector-store
  4. ›
  5. CVE-2026-40967

CVE-2026-40967: Spring AI has a VectorStore FilterExpression Converter injection

April 28, 2026 (updated May 6, 2026)

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query.

Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)

References

  • github.com/advisories/GHSA-qc4j-qjqx-vr58
  • github.com/spring-projects/spring-ai
  • nvd.nist.gov/vuln/detail/CVE-2026-40967
  • spring.io/security/cve-2026-40967

Code Behaviors & Features

Detect and mitigate CVE-2026-40967 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.0.0 before 1.0.6, all versions starting from 1.1.0 before 1.1.5

Fixed versions

  • 1.0.6
  • 1.1.5

Solution

Upgrade to versions 1.0.6, 1.1.5 or above.

Impact 8.6 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

maven/org.springframework.ai/spring-ai-vector-store/CVE-2026-40967.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:20:14 +0000.