Missing Authorization Affecting org.springframework.ai:spring-ai-openai package, versions [,1.0.7)[1.1.0-M1, 1.1.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKAI-16624639
  • published10 May 2026
  • disclosed8 May 2026
  • creditAhmed Sekka, sharlongwen

Introduced: 8 May 2026

NewCVE-2026-41712  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade org.springframework.ai:spring-ai-openai to version 1.0.7, 1.1.6 or higher.

Overview

org.springframework.ai:spring-ai-openai is an OpenAI models support

Affected versions of this package are vulnerable to Missing Authorization via the default configuration of the Spring AI chat memory component. An attacker can access data from other users when DEFAULT_CONVERSATION_ID is not explicitly overridden, leading to unintended cross-user data exposure.

Note: The upgrade fix for this vulnerability is a breaking change, due to the default conversationId behavior being removed. The recommendation is therefore to "ensure all ChatClient calls using memory advisors explicitly set the conversation identifier via .advisors(a -> a.param(ChatMemory.CONVERSATION_ID, id)) along with the upgrade.

CVSS Base Scores

version 4.0
version 3.1