Skip to content
VMwareCVE-2026-59308

VMware Spring AI: resource exposure

Medium4.2CVE-2026-59308 · Published Aug 21, 2026 · updated Sep 16, 2026

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

VMware advisory

Affected versions

PackageAffectedFixed in
Spring AI
Product
<= 2.0.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-668

More VMware advisories

All VMware
Advisory
VMware Micrometer: denial of service
Medium5.9Aug 24
VMware Spring AI: denial of service
High7.5Aug 21
VMware Spring AI: privilege escalation
Medium6.5Aug 21
VMware Micrometer: injection
Medium5.9Aug 21
VMware BOSH CLI: command injection
High7.5Aug 21
VMware Micrometer Tracing: denial of service
Medium5.3Aug 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.