CVE-2026-59308 PUBLISHED

Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation

Assigner: vmware
Reserved: 04.07.2026 Published: 21.08.2026 Updated: 21.08.2026

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 4.2

Product Status

Vendor Spring
Product Spring AI
Versions Default: unaffected
  • Version 2.0.0 is affected

References

Problem Types

  • Exposure of Resource to Wrong Sphere CWE

Impacts

  • In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.