Tracker / CVE-2026-40966
CVE-2026-40966
Medium 5.9
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Affected products and versions
| vmware | spring_ai · 1.0.0 → 1.0.6 |
|---|---|
| vmware | spring_ai · 1.1.0 → 1.1.5 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.