CVE-2026-22744: High severity maven/org.springframework/spring-ai-redis-store vulnerability
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22744?
CVE-2026-22744 has been classified as a high severity vulnerability due to its potential for injection attacks.
How do I fix CVE-2026-22744?
To mitigate CVE-2026-22744, upgrade to Spring AI version 1.0.5 or higher or 1.1.4 or higher.
What software is affected by CVE-2026-22744?
CVE-2026-22744 affects versions of the Spring AI Redis Store from 1.0.0 to 1.0.5 and from 1.1.0 to 1.1.4.
What type of attack does CVE-2026-22744 facilitate?
CVE-2026-22744 facilitates potential injection attacks due to unsanitized user input in TAG fields.
When was CVE-2026-22744 disclosed?
CVE-2026-22744 was disclosed as a security vulnerability on the date specified in the associated security advisory.