VMwareCVE-2026-59308
VMware Spring AI: resource exposure
Medium4.2CVE-2026-59308 · Published Aug 21, 2026 · updated Sep 16, 2026
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Spring AI Product | <= 2.0.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-668
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 24 | VMware Micrometer: denial of service | Medium5.9 | No fix yet |
| Aug 21 | VMware Spring AI: denial of service | High7.5 | No fix yet |
| Aug 21 | VMware Spring AI: privilege escalation | Medium6.5 | No fix yet |
| Aug 21 | VMware Micrometer: injection | Medium5.9 | No fix yet |
| Aug 21 | VMware BOSH CLI: command injection | High7.5 | 2.840.0 |
| Aug 21 | VMware Micrometer Tracing: denial of service | Medium5.3 | No fix yet |