Ghostwire

CVE-2026-40966: In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat...

MEDIUM CVSS 5.5 EPSS 0.04%

Published: April 28, 2026 | Last Modified: April 28, 2026

Description

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.04% (11th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References