CVE-2026-22744

In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
References
Link Resource
https://spring.io/security/cve-2026-22744 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-27 06:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22744

Mitre link : CVE-2026-22744

CVE.ORG link : CVE-2026-22744


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
NVD-CWE-noinfo CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')