CVE-2026-41712: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
Published May 12, 2026
·Updated
Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.
Affected Software
3 affected components
Spring Spring AI
VMware Spring Ai>=1.0.0<1.0.7
VMware Spring Ai>=1.1.0<1.1.6
Event History
May 12, 2026
CVE Published
via MITRE·10:17 AM
Data Sourced
via MITRE·10:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-41712?
CVE-2026-41712 has been classified with a high severity rating due to the potential for cross-user data leakage.
2
How do I fix CVE-2026-41712?
To fix CVE-2026-41712, explicitly override the DEFAULT_CONVERSATION_ID in the Spring AI chat memory configuration.
3
What impact does CVE-2026-41712 have on user privacy?
CVE-2026-41712 can lead to unintended data exposure between users, which significantly compromises user privacy.
4
Is there a patch available for CVE-2026-41712?
Yes, patches addressing CVE-2026-41712 are included in recent updates of Spring AI, so upgrading to the latest version is recommended.
5
Which versions of Spring AI are affected by CVE-2026-41712?
CVE-2026-41712 affects versions of Spring AI from 1.0.0 to 1.0.7 and 1.1.0 to 1.1.6.