CVE-2026-59308

Source
https://cve.org/CVERecord?id=CVE-2026-59308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59308
Published
2026-08-21T12:07:07Z
Modified
2026-09-18T03:48:30Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
Details

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

Database specific
{
    "cna_assigner":  "vmware",
    "cwe_ids":  [
        "CWE-668"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59308.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "2.0.0"
                },
                {
                    "last_affected":  "2.0.0"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-ai

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-ai
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "fixed":  "2.0.1"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59308.json"