spring-projects / spring-projects/spring-ai
Vulnerability fixing plan consultation
Open
Nobody has claimed this yet.
status: waiting-for-triage
- Dominant language
- Java
- Stars
- 9.5k
- Forks
- 2.9k
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 6
Description
CVE-2026-59318 has been fixed in version 2.0.1. Are there any plans to fix it in versions 1.0.x and 1.1.x?
How should SpringAi maintain the three version series: 1.0.x, 1.1.x, and 2.0.x?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or implementation entry point are identified. Start by reviewing CVE-2026-59318 and the support status of Spring AI versions 1.0.x, 1.1.x, and 2.0.x. Done would require an agreed maintenance or vulnerability-fix plan for the three version series.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100