CVE-2026-22730
EUVD-2026-1279718.03.2026, 08:16
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_ai | 1.0.0 ≤ 𝑥 < 1.0.4 |
| vmware | spring_ai | 1.1.0 ≤ 𝑥 < 1.1.3 |
𝑥
= Vulnerable software versions