Vulnerability Details CVE-2026-22738
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key are affected.
This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-22738
-
cpe:2.3:a:vmware:spring_ai:1.0.0
-
cpe:2.3:a:vmware:spring_ai:1.0.1
-
cpe:2.3:a:vmware:spring_ai:1.0.2
-
cpe:2.3:a:vmware:spring_ai:1.0.3
-
cpe:2.3:a:vmware:spring_ai:1.0.4
-
cpe:2.3:a:vmware:spring_ai:1.1.0
-
cpe:2.3:a:vmware:spring_ai:1.1.1
-
cpe:2.3:a:vmware:spring_ai:1.1.2
-
cpe:2.3:a:vmware:spring_ai:1.1.3