CVE-2026-22730 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arb…
High CVSS: 8.8

CVE-2026-22730

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.

The vulnerability exists due to missing input sanitization.
Vendor
Vmware
Product
Spring Ai
CWE
CWE-89
Yayın Tarihi
2026-03-18 08:16:31
Güncelleme
2026-04-01 16:52:48
Source Identifier
security@vmware.com
KEV Date Added
-

Kategoriler

Referanslar