VORANT. Threat Intelligence Sign in Get the full feed

Spring AI SQLi flaw bypasses security policy

medium vulnerability

A SQL injection vulnerability in Spring AI versions before 1.0.9 and 1.1.8 allows attackers to bypass security policies.

The French national CERT has issued an advisory for a SQL injection vulnerability in Spring AI, tracked as CVE-2026-47835. The flaw affects Spring AI versions 1.0.x prior to 1.0.9 and versions 1.1.x prior to 1.1.8. Successful exploitation allows an attacker to perform SQL injection attacks and bypass the application's security policy.

The vulnerability represents a standard injection weakness in the Spring AI framework. Organizations using affected versions should prioritize patching, as SQL injection vulnerabilities can lead to unauthorized data access, data manipulation, and potential escalation of privileges depending on database configuration and application context.

Spring has released security patches in versions 1.0.9 and 1.1.8 to address the vulnerability. Users are advised to consult the vendor's security bulletin for detailed remediation guidance and upgrade to the patched versions.

Mentioned in this report

Vulnerabilities CVE-2026-47835

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0751

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free