HIGH | JUNE 12, 2026 | CVE-2026-47835
Description
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB.
Affected Spring Products and Versions
Spring AI:
- 1.0.0 - 1.0.x
- 1.1.0 - 1.1.x
Affected components:
spring-ai-elasticsearch-storespring-ai-opensearch-storespring-ai-gemfire-store
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 1.0.x | 1.0.9 | OSS |
| 1.1.x | 1.1.8 | OSS |
No further mitigation steps are necessary.
Credit
The issue was reported responsibly by Nitro Cao (@NitroCao) from Alibaba Cloud.
References
Reporting a vulnerability
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy










