Skip to content
MindPattern
Wire
Briefings
Search
Subscribe
← The Wire
Source trail
Spring Security Advisories
Public MindPattern findings, entities, and graph evidence that cite this source.
Findings
1
All-time hits
1
High value
0
Last seen
2026-08-24
Related findings
2026-08-24 / TOOLS
Spring AI 2.0.0 MCP Server Transport Retains Sessions Without Limit (CVE-2026-59279)
Spring disclosed CVE-2026-59279 on 2026-08-20 with a CVSS 3.1 base of 7.5: the MCP Streamable HTTP server transport in both the WebFlux and WebMvc variants places no cap on retained sessions and does not require client authentication by default. A remote attacker sends repeated `initialize` requests until memory is exhausted, taking down every session on the server. Fixed in 2.0.1 OSS and 2.0.0.1 Enterprise, with no mitigation short of upgrading.
Open latest cited source
Wire
Briefings
Search
Subscribe