CVE-2026-47835
Received
Received - Intake
BaseFortify
Publication date: 2026-06-15
Last updated on: 2026-06-15
Assigner: VMware
Description
Description
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store.
Affected versions:
Spring AI 1.0.0 through 1.0.x (fix 1.0.9).
Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| spring_ai | spring_ai_elasticsearch_store | * |
| spring_ai | spring_ai_opensearch_store | * |
| spring_ai | spring_ai_gemfire_store | * |
| spring_ai | spring_ai | From 1.0.0 (inc) to 1.0.9 (inc) |
| spring_ai | spring_ai | From 1.1.0 (inc) to 1.1.8 (inc) |
| elasticsearch | elasticsearch | * |
| opensearch | opensearch | * |
| gemfire | gemfire | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-943 | The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query. |