CVE-2026-40990: Unbounded cache for function definitions

MODERATE | MAY 08, 2026 | CVE-2026-40990
Description OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions Spring Cloud Function 3.2.x 4.2.x 4.3.x 5.0.x Older, unsupported versions are also affected Mitigation Users of…

CVE-2026-40967: VectorStore FilterExpression Converter injection

HIGH | APRIL 27, 2026 | CVE-2026-40967
Description In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all