PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47851 Spring CVE debrief

A StackOverflowError can occur in the ingestion thread when analyzing a PDF with a deeply nested or cyclic table of contents. This issue affects Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0. The vulnerability has a high CVSS score of 7.5, indicating a high-priority defensive action is recommended. Users of Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0 should be aware of this vulnerability and take necessary defensive actions. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Affected product deployments should be confirmed to exist in managed environments and assigned an owner for follow-up. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review.

Vendor
Spring
Product
Spring AI
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-04
Advisory published
2026-08-27
Advisory updated
2026-09-04

Who should care

Users of Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0 should be aware of this vulnerability and take necessary defensive actions. Affected operator, platform, vulnerability-management, and security-team impact should be considered. Defensive priority is high due to the potential for denial-of-service attacks. Confidentiality, integrity, and availability may be impacted. Security teams should review and update incident response plans to address potential attacks. IT operations should monitor systems for suspicious activity and implement compensating controls to detect and prevent potential attacks. Developers should apply vendor-provided patches or updates to affected systems. Security teams should also review compensating controls for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review. Security teams should also consider reviewing and updating incident response plans to address potential attacks. Security teams should also consider implementing additional security controls to prevent similar attacks in the future. Security teams should also consider conducting a thorough risk assessment to identify potential vulnerabilities and implement mitigation strategies. Security teams should also consider reviewing and updating their vulnerability management processes to ensure that similar vulnerabilities are addressed in a timely manner. Security teams should also consider providing additional training to developers and IT operations on secure coding practices and secure system configuration. Security teams should also consider implementing a continuous monitoring program to detect and respond to potential security incidents in a timely manner. Security teams should also consider reviewing and updating their incident response plans to ensure that they are prepared to respond to potential security incidents. Security teams should also consider conducting regular security audits to identify potential vulnerabilities and implement mitigation strategies. Security teams should also consider implementing a vulnerability management program to

Technical summary

A StackOverflowError can occur in the ingestion thread when analyzing a PDF with a deeply nested or cyclic table of contents. This issue affects Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0. The vulnerability has a high CVSS score of 7.5, indicating a high-priority defensive action is recommended. Users of Spring AI versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0 should be aware of this vulnerability and take necessary defensive actions.

Defensive priority

High-priority defensive actions are recommended due to the high CVSS score of 7.5 and the potential for denial-of-service attacks.

Recommended defensive actions

  • Inventory and verify affected Spring AI versions
  • Apply vendor-provided patches or updates
  • Implement compensating controls to detect and prevent potential attacks
  • Monitor systems for suspicious activity
  • Review and update incident response plans

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further analysis and verification are necessary to fully understand the issue. Affected product deployments should be confirmed to exist in managed environments and assigned an owner for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. Vendor-supported updates or mitigations should be planned through normal change control where exposure is confirmed. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs should be checked for exposed assets that need extra review.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47851 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47851

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47851 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47851

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.