MCP Streamable HTTP 服务器传输(包括 WebFlux 和 WebMvc 两种变体)对其保留的会话数量未设置任何限制,并且默认情况下不要求客户端进行身份验证。因此,远程攻击者可以通过随时间推移不断发起会话,导致服务器累积无限数量的会话,逐渐耗尽可用内存,最终引发拒绝服务(DoS),影响所有合法客户端。 受影响版本: Spring AI:2.0.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59318 | 6.5 MEDIUM | DefaultToolCallingManager Global Resolver Fallback Allows Unadvertised Tool Dispatch via P |
| CVE-2026-59308 | 4.2 MEDIUM | Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation |
No comments yet