Data Exposure Vulnerability in Spring AI by Pivotal Software
CVE-2026-40979
6.1MEDIUM
What is CVE-2026-40979?
A data exposure vulnerability in Spring AI could allow unauthorized access to ONNX models utilized by the application when deployed in a shared environment. This may lead to sensitive data being revealed to malicious actors. Users are advised to upgrade to version 1.0.6 or 1.1.5 to mitigate this risk.
Affected Version(s)
Spring AI 1.0.0 < 1.0.6
Spring AI 1.1.0 < 1.1.5
