VDB
CVE-2026-40966
CVE-2026-40966
PUBLISHED
CVSS 5.900000095367432 MEDIUM
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
EPSS 0.23% · 14.2th percentile
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.23%
14.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| VMware | Spring AI | 1.0.0, 1.1.0 |
Timeline
- CVE Published
- Apr 28, 2026 PoC Published
- May 7, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://spring.io/security/cve-2026-40980 advisory
- https://spring.io/security/cve-2026-40978 advisory
- https://spring.io/security/cve-2026-40969 advisory
- https://spring.io/security/cve-2026-40967 advisory
- https://spring.io/security/cve-2026-40966 url
- https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?version=3.1&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N url
- https://spring.io/security/cve-2026-40979 advisory
- https://spring.io/security/cve-2026-40968 advisory