# Spring AI versions 1.1.x before 1.1.7 contain a vulnerability (CVE-2026-41863) allowing…

Published: 2026-05-26 · Severity: medium
Canonical: https://vorant.io/reports/71a7cd8a-fba3-4118-bb88-a11db87c9f1d/spring-ai-versions-1-1-x-before-1-1-7-contain-a-vulnerability-cve-2026-41863

> Spring AI versions 1.1.x before 1.1.7 contain a vulnerability (CVE-2026-41863) allowing attackers to compromise data integrity.

The French CERT (CERT-FR) has published an advisory regarding a vulnerability in Spring AI, a framework for building AI-powered applications. The vulnerability affects Spring AI versions 1.1.x prior to version 1.1.7 and enables an attacker to compromise the integrity of data within affected systems.

The advisory classifies this as a data integrity risk, though specific exploitation details and attack vectors are not provided in the published notice. Organizations using affected versions of Spring AI are advised to consult the vendor security bulletin for patching guidance.

Spring has released a security bulletin addressing CVE-2026-41863 on May 23, 2026. Users should upgrade to Spring AI version 1.1.7 or later to remediate this vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2026-41863

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0646

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/71a7cd8a-fba3-4118-bb88-a11db87c9f1d/spring-ai-versions-1-1-x-before-1-1-7-contain-a-vulnerability-cve-2026-41863.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
