CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22730?
CVE-2026-22730 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-22730?
To fix CVE-2026-22730, ensure proper input sanitization and update to the latest version of Spring AI that addresses this issue.
What software is affected by CVE-2026-22730?
CVE-2026-22730 affects the Spring AI framework's MariaDBFilterExpressionConverter component.
What kind of attack can be executed due to CVE-2026-22730?
CVE-2026-22730 allows attackers to execute arbitrary SQL commands by bypassing metadata-based access controls.
When was CVE-2026-22730 reported?
CVE-2026-22730 was reported as a vulnerability that exposes critical data handling flaws in Spring AI.