maven package report

Is dev.langchain4j:langchain4j-pgvector safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 38th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-2mfg-cc43-9pcj, the advisory selected below

      // 1 advisories

      GHSA-2mfg-cc43-9pcj

      HIGHCVE-2026-55405
      // summary

      The MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys (and, in MariaDB, string values) directly into the query without adequate escaping. A crafted metadata key in EmbeddingSearchRequest.filter() can break out of its SQL context and inject arbitrary SQL into the statements executed by the stores' search and removeAll(Filter) operations.

      // details

      pgvector — JSON mode (default, COMBINEDJSON / COMBINEDJSONB). JSONFilterMapper places the key inside a single-quoted SQL literal (the JSON key of the ->> operator) with no escaping:

      (metadata->>'')::text

      A key containing a single quote breaks out, e.g. metadataKey("')::text IS NOT NULL OR pgsleep(1) IS NOT NULL --") injects a live pgsleep(1) (observable as a delay; exploitable for blind data extraction).

      pgvector — column mode (COLUMNPERKEY). ColumnFilterMapper used the key as a bare, unquoted, unvalidated SQL identifier (::), so a key such as 1=1 OR true -- injects directly.

      MariaDB — JSON mode (default). JSONFilterMapper placed the key inside the JSON path literal '$.' unescaped (same break-out mechanism). Additionally, MariaDbFilterMapper.formatValue() escaped ' but not \; because MariaDB treats backslash as an escape character by default, a string value ending in a backslash could also break out of its literal.

      MariaDB — column mode (COLUMNPERKEY). ColumnFilterMapper fell back to the raw, unescaped key when the driver could not quote it as an identifier (e.g. a character).

      The filter key is the runtime injection surface; both stores' search() (including pgvector's HYBRID mode) and removeAll(Filter) are affected. Add/upsert operations a parameterized and not affected.

      // impact

      Applications that allow attacker-influenced metadata filter keys (e.g. use LLM-generated filters) to reach these stores are exposed to SQL injection: blind data exfiltration, denial of service via sleep functions, and — through remove deletion of arbitrary rows. Applications using only hard-coded, developer-defined filter keys are not reachable.

      // patches

      Fixed in langchain4j-mariadb and langchain4j-pgvector 1.16.3-beta26:

      • JSON filter keys are escaped before being embedded in the SQL string lit

      quotes doubled, correct for PostgreSQL standardconformingstrings = on; MariaDB: backslash and single quote).

      • MariaDB string values escape both \ and '.
      • Column-mode keys are validated/quoted as identifiers and rejected when u

      concatenated as raw SQL.

      // workarounds
      • Do not pass untrusted input as metadata filter keys.
      • Restrict filter keys to a known allow-list at the application layer.
      // references
      • pgvector: JSONFilterMapper, ColumnFilterMapper
      • MariaDB: JSONFilterMapper, MariaDbFilterMapper, ColumnFilterMapper
      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      Low
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      High
      Integrity
      Low
      Availability
      Low

      Checked 2026-09-26 at 02:00 UTC. The most recent advisory here was published 2026-06-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.