vmware / spring_ai
9 known vulnerabilities in vmware spring_ai.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-59279 | Medium | 0.4% | 7.5 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not … | |
| CVE-2026-41705 | Medium | 0.4% | 8.6 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to fil… | |
| CVE-2026-47851 | Medium | 0.3% | 7.5 | Analyzing a PDF with a deeply nested or cyclic table of contents can cause a Sta… | |
| CVE-2026-47852 | Medium | 0.2% | 7.5 | A local attacker on a multi-user host can pre-create the deterministic cache pat… | |
| CVE-2026-41863 | Low | 0.4% | 6.5 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames uns… | |
| CVE-2026-59294 | Low | 0.3% | 5.9 | ResourceCacheService.getCacheName() builds the on-disk filename by appending the… | |
| CVE-2026-59319 | Low | 0.2% | 4.3 | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text querie… | |
| CVE-2026-59318 | Low | 0.2% | 6.5 | In Spring AI's tool calling support, the per-request tool list is advertised to … | |
| CVE-2026-59308 | Low | 0.2% | 4.2 | In Spring AI's Semantic Cache support, the context hash used to isolate cached r… |