{"api_version":"v1","generated_at":"2026-10-08T14:05:00+00:00","product":{"cve_count":18,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-spring-spring-ai-f60974535484","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Spring AI","next_cursor":null,"observations":[{"affected":"2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-59319","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59319","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T22:47:00.784Z","patch_url":"","primary_source":"","published":"2026-08-27T18:04:46.944Z"},{"affected":"2.0.0; 1.1.0 \u2264 1.1.8; \u2264 1.0.9","affected_versions_present":true,"cve_id":"CVE-2026-59294","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59294","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T18:36:07.272Z","patch_url":"","primary_source":"","published":"2026-08-27T17:57:52.047Z"},{"affected":"2.0.0; 1.1.0 \u2264 1.1.8; 1.0.0 \u2264 1.0.9","affected_versions_present":true,"cve_id":"CVE-2026-47852","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47852","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-27T15:13:55.925Z","patch_url":"","primary_source":"","published":"2026-08-26T23:28:42.767Z"},{"affected":"2.0.0; 1.1.0 \u2264 1.1.8; 1.0.0 \u2264 1.0.9","affected_versions_present":true,"cve_id":"CVE-2026-47851","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47851","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-27T15:14:42.087Z","patch_url":"","primary_source":"","published":"2026-08-26T23:28:41.732Z"},{"affected":"Spring AI: 2.0.0, 1.1.0 \u2264 1.1.8, 1.0.0 \u2264 1.0.9","affected_versions_present":true,"cve_id":"CVE-2026-59318","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59318","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-22T03:55:38.874Z","patch_url":"","primary_source":"","published":"2026-08-21T12:07:10.349Z"},{"affected":"Spring AI: 2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-59308","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59308","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T14:29:06.814Z","patch_url":"","primary_source":"","published":"2026-08-21T12:07:07.992Z"},{"affected":"Spring AI: 2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-59279","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59279","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T14:28:41.415Z","patch_url":"","primary_source":"","published":"2026-08-21T12:07:05.567Z"},{"affected":"1.0.0 < 1.0.9; 1.1.0 < 1.1.8","affected_versions_present":true,"cve_id":"CVE-2026-47835","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47835","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T20:06:56.646Z","patch_url":"","primary_source":"","published":"2026-06-15T18:54:19.841Z"},{"affected":"1.1.0 \u2264 1.1.x","affected_versions_present":true,"cve_id":"CVE-2026-41863","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41863","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T14:19:10.481Z","patch_url":"","primary_source":"","published":"2026-05-25T05:45:37.690Z"},{"affected":"1.0.0 < 1.0.7; 1.1.0 < 1.1.6","affected_versions_present":true,"cve_id":"CVE-2026-41705","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41705","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-11T14:38:29.738Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-443","primary_source":"","published":"2026-05-09T00:34:17.870Z"},{"affected":"1.0.0 < 1.0.6; 1.1.0 < 1.1.5","affected_versions_present":true,"cve_id":"CVE-2026-40980","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40980","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T12:32:40.140Z","patch_url":"","primary_source":"","published":"2026-04-28T07:31:24.041Z"},{"affected":"1.0.0 < 1.0.6; 1.1.0 < 1.1.5","affected_versions_present":true,"cve_id":"CVE-2026-40979","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40979","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T12:33:07.977Z","patch_url":"","primary_source":"","published":"2026-04-28T07:31:21.447Z"},{"affected":"1.0.0 < 1.0.6; 1.1.0 < 1.1.5","affected_versions_present":true,"cve_id":"CVE-2026-40978","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40978","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T03:55:35.548Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-397","primary_source":"","published":"2026-04-28T07:18:53.774Z"},{"affected":"1.0.0 < 1.0.6; 1.1.0 < 1.1.5","affected_versions_present":true,"cve_id":"CVE-2026-40967","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40967","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T13:29:47.165Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-397","primary_source":"","published":"2026-04-28T06:03:51.857Z"},{"affected":"1.0.0 < 1.0.5; 1.1.0 < 1.1.4","affected_versions_present":true,"cve_id":"CVE-2026-22744","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22744","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-02T16:05:50.935Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-288","primary_source":"","published":"2026-03-27T05:38:59.633Z"},{"affected":"1.0.0 < 1.0.5; 1.1.0 < 1.1.4","affected_versions_present":true,"cve_id":"CVE-2026-22743","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22743","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T19:38:58.544Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-288","primary_source":"","published":"2026-03-27T05:33:20.872Z"},{"affected":"1.0.0 < 1.0.5; 1.1.0 < 1.1.4","affected_versions_present":true,"cve_id":"CVE-2026-22742","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22742","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-10T13:03:54.063Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-288","primary_source":"","published":"2026-03-27T05:27:41.165Z"},{"affected":"1.0.0 < 1.0.5; 1.1.0 < 1.1.4","affected_versions_present":true,"cve_id":"CVE-2026-22738","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22738","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-10T13:04:38.045Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-288","primary_source":"","published":"2026-03-27T05:21:07.168Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Spring"}}
