spring-ai-client-chat is vulnerable to Denial of Service (DoS)
65
Medium Risk
Affected versions of Spring AI are vulnerable to Denial of Service (DoS). A malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by ForkPDFLayoutTextStripper.
You are affected if using a vulnerable version and your applications uses ForkPDFLayoutTextStripper and pass user-supplied input to DocumentReaders.
spring-ai-client-chat is vulnerable to Denial of Service (DoS) in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant