CVE-2026-47835: Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store.
Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
spring-ai-elasticsearch-storeto a version that resolves this vulnerability.Fixed in 1.0.9 - Upgrade
Upgrade
spring-ai-elasticsearch-storeto a version that resolves this vulnerability.Fixed in 1.1.8 - Upgrade
Upgrade
spring-ai-opensearch-storeto a version that resolves this vulnerability.Fixed in 1.0.9 - Upgrade
Upgrade
spring-ai-opensearch-storeto a version that resolves this vulnerability.Fixed in 1.1.8 - Upgrade
Upgrade
spring-ai-gemfire-storeto a version that resolves this vulnerability.Fixed in 1.0.9 - Upgrade
Upgrade
spring-ai-gemfire-storeto a version that resolves this vulnerability.Fixed in 1.1.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47835?
CVE-2026-47835 has a high severity rating of 8.6.
What components are affected by CVE-2026-47835?
CVE-2026-47835 affects spring-ai-elasticsearch-store, spring-ai-opensearch-store, and spring-ai-gemfire-store.
How do I fix CVE-2026-47835?
To fix CVE-2026-47835, upgrade to the latest patched version of the affected Spring AI components.
What type of vulnerability is CVE-2026-47835?
CVE-2026-47835 is a security vulnerability that allows the execution of arbitrary queries due to improper handling of special characters.
Is user interaction required to exploit CVE-2026-47835?
No, CVE-2026-47835 does not require user interaction to be exploited.