CVE-2026-59308

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
References
Link Resource
https://spring.io/security/cve-2026-59308 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*

History

16 Sep 2026, 14:06

Type Values Removed Values Added
References () https://spring.io/security/cve-2026-59308 - () https://spring.io/security/cve-2026-59308 - Vendor Advisory
CPE cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*
First Time Vmware spring Ai
Vmware

Information

Published : 2026-08-21 12:16

Updated : 2026-09-16 14:06


NVD link : CVE-2026-59308

Mitre link : CVE-2026-59308

CVE.ORG link : CVE-2026-59308


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-668

Exposure of Resource to Wrong Sphere