Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59279— Unbounded persistent session allocation via repeated initialize requests

Quick assessment

Affected
Spring Spring AI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MCP Streamable HTTP 服务器传输(包括 WebFlux 和 WebMvc 两种变体)对其保留的会话数量未设置任何限制,并且默认情况下不要求客户端进行身份验证。因此,远程攻击者可以通过随时间推移不断发起会话,导致服务器累积无限数量的会话,逐渐耗尽可用内存,最终引发拒绝服务(DoS),影响所有合法客户端。 受影响版本: Spring AI:2.0.0

CVSS 7.5 · High EPSS 0.39% · P32

Affected Version Matrix 1

VendorProduct Version RangeStatus
Spring Spring AI 2.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59279

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unbounded persistent session allocation via repeated initialize requests
Source: CVE Program / CVE List V5
Vulnerability Description
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Spring Spring AI 2.0.0 -

II. Public POCs for CVE-2026-59279

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59279

登录查看更多情报信息。

Vendor Advisories for CVE-2026-59279 (1)

Same Patch Batch · Spring · 2026-08-21 · 3 CVEs total

CVE-2026-59318 6.5 MEDIUM DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via P
CVE-2026-59308 4.2 MEDIUM Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation

IV. Related Vulnerabilities

V. Comments for CVE-2026-59279

No comments yet


Leave a comment