Vulnerability Details CVE-2026-59308
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.
Affected versions:
Spring AI: 2.0.0
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 5.4%
CVSS Severity
CVSS v3 Score 4.2
Products affected by CVE-2026-59308
-
cpe:2.3:a:vmware:spring_ai:2.0.0