Impact
This vulnerability arises when the Spring AI PDF Document Reader processes a PDF containing a deeply nested or cyclic table of contents, leading to unbounded recursion and a StackOverflowError in the ingestion thread. The resulting crash can expose the application to a denial‑of‑service condition for any user relying on PDF ingestion. It does not provide an attacker with execution privileges or code execution; the failure is limited to service availability.
Affected Systems
The affected product is Spring AI, versions 1.0.0 through 1.0.9, 1.1.0 through 1.1.8, and 2.0.0. All affected builds are distributed under the Spring label.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests no widespread exploitation has been documented to date. The attack vector is inferred to be remote, requiring an attacker to supply a crafted PDF file to the ingestion component; successful exploitation would result in a stack overflow and potential service disruption.
OpenCVE Enrichment