Vulnerability intelligence
CVE-2026-59279
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
CVSS Score
7.5
High
EPSS — Exploit Probability
0.5%
Riskier than 44% of all CVEs · checked 2026-10-04
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 21, 2026 · latest Aug 21, 2026
Coverage timeline
-
VMware fixes high severity Spring flaws after August 2026 alertsecurityonline.info · Aug 21, 2026