Spring AI 2.0.0 Semantic Cache Context Hash Flaw: Cross-Context Leakage
CVE-2026-59308 Published on August 21, 2026

Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

NVD

Vulnerability Analysis

CVE-2026-59308 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.


Affected Versions

Spring AI Version 2.0.0 is affected by CVE-2026-59308