Spring AI 2.0.0 Semantic Cache Context Hash Flaw: Cross-Context Leakage
CVE-2026-59308 Published on August 21, 2026
Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.
Affected versions:
Spring AI: 2.0.0
Vulnerability Analysis
CVE-2026-59308 is exploitable with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.