CVE-2026-59279

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
References
Link Resource
https://spring.io/security/cve-2026-59279 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*

History

16 Sep 2026, 14:06

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*
First Time Vmware spring Ai
Vmware
References () https://spring.io/security/cve-2026-59279 - () https://spring.io/security/cve-2026-59279 - Vendor Advisory

Information

Published : 2026-08-21 12:16

Updated : 2026-09-16 14:06


NVD link : CVE-2026-59279

Mitre link : CVE-2026-59279

CVE.ORG link : CVE-2026-59279


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-770

Allocation of Resources Without Limits or Throttling