Skip to content
VMwareCVE-2026-59279

VMware Spring AI: denial of service

High7.5CVE-2026-59279 · Published Aug 21, 2026 · updated Sep 16, 2026

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0

VMware advisory

Affected versions

PackageAffectedFixed in
Spring AI
Product
<= 2.0.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More VMware advisories

All VMware
Advisory
VMware Micrometer: denial of service
Medium5.9Aug 24
VMware Spring AI: resource exposure
Medium4.2Aug 21
VMware Spring AI: privilege escalation
Medium6.5Aug 21
VMware Micrometer: injection
Medium5.9Aug 21
VMware BOSH CLI: command injection
High7.5Aug 21
VMware Micrometer Tracing: denial of service
Medium5.3Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.