# Spring AI SQLi flaw enables security bypass

Published: 2026-06-15 · Severity: medium
Canonical: https://vorant.io/reports/fead4e23-4e86-512e-a569-d9a197df65de/spring-ai-sqli-flaw-enables-security-bypass

> A SQL injection vulnerability in Spring AI versions before 1.0.9 and 1.1.8 allows attackers to bypass security policies and execute arbitrary SQL queries.

CERT-FR has published an advisory regarding a security vulnerability affecting Spring AI framework. The flaw, tracked as CVE-2026-47835, enables SQL injection attacks that can lead to security policy bypass. The vulnerability impacts Spring AI versions 1.0.x prior to 1.0.9 and versions 1.1.x prior to 1.1.8.

Organizations using affected versions of Spring AI should prioritize patching to the latest releases. The vulnerability's combination of SQL injection and security policy bypass capabilities presents a significant risk to applications built on the framework. Spring has published security guidance and patches to address the issue.

The advisory recommends consulting Spring's official security bulletin for detailed remediation steps and obtaining the necessary patches to secure vulnerable deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47835

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0751/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fead4e23-4e86-512e-a569-d9a197df65de/spring-ai-sqli-flaw-enables-security-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
