CVE-2026-55405: LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores buil...

Added to the CISA Known Exploited Vulnerabilities catalog on 10 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.6.

LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly in...

Required action: Review and patch if applicable to your AI infrastructure.