Intel

AIKIDO-2026-10674

spring-ai-client-chat is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-40980 Published Apr 30, 2026

65

Medium Risk

This Affects:

JAVAspring-ai-client-chat
1.0.0 - 1.0.5
Fixed in 1.0.6
1.1.0 - 1.1.4
Fixed in 1.1.5
Are you affected? Scan for Free

TL;DR

Affected versions of Spring AI are vulnerable to Denial of Service (DoS). A malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by ForkPDFLayoutTextStripper.

Who does this affect?

You are affected if using a vulnerable version and your applications uses ForkPDFLayoutTextStripper and pass user-supplied input to DocumentReaders.

Background info

spring-ai-client-chat is vulnerable to Denial of Service (DoS) in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.

How to fix this

Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.