Cache Isolation Vulnerability in Spring AI by Pivotal Software
CVE-2026-59308

4.2MEDIUM

Key Information:

Vendor

Spring

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-59308?

A vulnerability in Spring AI's Semantic Cache support allows the potential for cached responses to be inadvertently shared across unrelated system prompts due to improper isolation of context hashes. This can lead to scenarios where sensitive or contextual information may be exposed unintentionally, thus undermining the privacy and integrity of the system’s operations.

Affected Version(s)

Spring AI 2.0.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.