SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59308

MEDIUM · CVSS 4.2 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in Spring AI's Semantic Cache support allows cached responses to be improperly shared across unrelated contexts due to a flaw in the context hash isolation mechanism. This could lead to unintended data exposure, where sensitive information from one prompt may be accessible in another, potentially compromising user privacy and data integrity. Organizations using Spring AI version 2.0.0 should prioritize addressing this issue to mitigate the risks associated with unauthorized data sharing.

CVE
CVE-2026-59308
Severity
MEDIUM
CVSS
4.2
EPSS
0.16%

Original NVD Description

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

Related CVEs

Other vulnerabilities affecting the same vendor(s)