{"id":"CVE-2026-59308","title":"In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.\nAffected versions:\nSpring AI: 2.0.0","summary":"In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.\nAffected versions:\nSpring AI: 2.0.0","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-668"],"vendor":"vmware","product":"spring_ai","affected":["spring_ai >= 2.0.0, < 2.0.1"],"patched":["spring_ai 2.0.1"],"published":"2026-08-21","updated":"2026-09-16","sourceUpdated":"2026-09-16T14:06:31.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59308","references":[{"url":"https://spring.io/security/cve-2026-59308","label":"security@vmware.com"}],"tags":["nvd"],"epss":0.00163,"epssPercentile":0.05908,"ingestedAt":"2026-09-16T14:57:28.003Z","slug":"CVE-2026-59308","body":"## Overview\n\nIn Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.\nAffected versions:\nSpring AI: 2.0.0\n\n## Affected\n\n- `spring_ai >= 2.0.0, < 2.0.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_ai 2.0.1`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}