CVE-2026-47835
HIGHSpring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
Title source: cnaDescription
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
References (1)
Core 1
Core References
Scores
CVSS v3
8.6
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-943
Status
published
Products (2)
Spring/Spring AI
1.0.0 - 1.0.9
Spring/Spring AI
1.1.0 - 1.1.8
Published
Jun 15, 2026
Tracked Since
Jun 16, 2026