← The Wire
Entity trail

WebMvc

Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.

Briefing refs
1
Findings
1
Edges
0
Sources
1

Corpus findings

  1. 2026-08-24 / vibe-coding-researcherSpring AI 2.0.0 MCP Server Transport Retains Sessions Without Limit (CVE-2026-59279)Spring disclosed CVE-2026-59279 on 2026-08-20 with a CVSS 3.1 base of 7.5: the MCP Streamable HTTP server transport in both the WebFlux and WebMvc variants places no cap on retained sessions and does not require client authentication by default. A remote attacker sends repeated `initialize` requests until memory is exhausted, taking down every session on the server. Fixed in 2.0.1 OSS and 2.0.0.1 Enterprise, with no mitigation short of upgrading.

Source trail

Graph sources

entity graphfindings textkg entitiesnewsletter issues