VDB
GHSA-v6x6-pjxw-3pv2
GHSA-v6x6-pjxw-3pv2
PUBLISHED
CVSS 5.900000095367432 MEDIUM
Spring AI's VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.springframework.ai:spring-ai-advisors-vector-store | 1.0.0, 1.1.0, 1.0.0 |
Timeline
- Apr 28, 2026 CVE Published
- May 7, 2026 Security Advisory
- Jul 17, 2026 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-40966 advisory
- https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?version=3.1&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N url
- https://github.com/spring-projects/spring-ai package
- https://jinyeong.seol.pro/blogs/cve-2026-40966/en url
- https://spring.io/security/cve-2026-40966 url