CVE-2026-40980: Medium severity maven/org.springframework/spring-ai vulnerability
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by ForkPDFLayoutTextStripper.
Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40980?
CVE-2026-40980 is considered to have a high severity due to its potential to cause excessive memory allocation from malicious PDF files.
How do I fix CVE-2026-40980?
To fix CVE-2026-40980, upgrade Spring AI to version 1.0.6 or 1.1.5 or later.
What versions are affected by CVE-2026-40980?
CVE-2026-40980 affects Spring AI versions 1.0.0 to 1.0.5 and 1.1.0 to 1.1.4.
What component of Spring AI is vulnerable in CVE-2026-40980?
The vulnerability in CVE-2026-40980 specifically involves the `ForkPDFLayoutTextStripper` component.
What can happen if CVE-2026-40980 is exploited?
Exploitation of CVE-2026-40980 can lead to denial of service due to resource exhaustion caused by handling specially crafted PDF files.