Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage

GHSA-q62f-h9x2-gcqc · CVE-2026-41712

Published · Modified

Description

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

Ready to move

Start Securing

Free, no credit card | First findings in minutes