CyberRota
Back to database

CVE-2026-40980

MEDIUM · CVSS 6.5 EPSS 0.06%

Source: NVD + CISA KEV + EPSS · Published: 2026-04-28 · Last synced: 2026-05-28

CyberRota Analysis

Bellek tüketimine neden olabilir.

CVE
CVE-2026-40980
Severity
MEDIUM
CVSS
6.5
EPSS
0.06%

Original NVD Description

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)