CVE-2026-47835: VMware Spring Ai
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
Affected products
- VMware Spring Ai: from 1.0.0, before 1.0.9 (fixed in 1.0.9); from 1.1.0, before 1.1.8 (fixed in 1.1.8)
Published 2026-06-15. Last modified 2026-06-17.