CVE-2026-47851: Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using the Spring AI PDF Document Reader to analyze PDFs are exposed when they process a PDF whose table of contents is deeply nested or cyclic. The issue can be triggered remotely without authentication or user interaction according to the supplied vector.
What is the likely impact of successful exploitation?
Processing a malicious PDF can cause a StackOverflowError in the ingestion thread, resulting in a denial of service for that thread. The provided severity vector indicates no confidentiality or integrity impact.
Which releases are affected?
The affected releases listed are Spring AI 2.0.0, Spring AI 1.1.0 through 1.1.8, and Spring AI 1.0.0 through 1.0.9.