Stack Overflow Error in Spring AI due to Nested Table of Contents
CVE-2026-47851

7.5HIGH

Key Information:

Vendor

Spring

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-47851?

Processing PDFs with deeply nested or cyclic tables of contents in Spring AI can lead to a StackOverflowError, causing potential disruptions in the ingestion thread. This vulnerability may adversely impact applications that rely on Spring AI for document handling and analysis, emphasizing the need for immediate attention and resolution.

Affected Version(s)

Spring AI 2.0.0

Spring AI 1.1.0 <= 1.1.8

Spring AI 1.0.0 <= 1.0.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.