# CVE-2026-59308

## Summary

- **CVE ID:** CVE-2026-59308
- **Severity:** MEDIUM
- **CVSS Score:** 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **CWE:** CWE-668
- **Published:** Aug 21, 2026
- **Last Modified:** Aug 21, 2026

## Description

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts.
Affected versions:
Spring AI: 2.0.0

## Affected Products

- Spring — Spring AI (2.0.0)

## References

- [CNA](https://spring.io/security/cve-2026-59308)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._