github.com
https://github.com/spring-projects/spring-ai CVE-2026-40966
MEDIUM
VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration
Record summary
CVE-2026-40966 has a selected CVSS score of 5.9 (medium).
Description
In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 28, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Spring AIBrowse VMware / Spring AIDefault status: unaffected | CVE List | 1.0.0 to < 1.0.6 | affected |
| 1.1.0 to < 1.1.5 | affected | ||
org.springframework.ai:spring-ai-advisors-vector-storeBrowse Maven / org.springframework.ai:spring-ai-advisors-vector-store | GitHub Advisory | 1.0.0 to < 1.0.6 · Fixed in 1.0.6 | affected |
| 1.1.0 to < 1.1.5 · Fixed in 1.1.5 | affected |
References
5jinyeong.seol.pro
https://jinyeong.seol.pro/blogs/cve-2026-40966/en nvd.nist.gov
https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?version=3.1&vector=AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-40966 spring.io
https://spring.io/security/cve-2026-40966