云虫漏洞库

CVE-2026-59279 - The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0 - 漏洞详情

漏洞编号:CVE-2026-59279

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-59279

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-770

发布/更新时间:2026-08-21 / 2026-08-28

漏洞描述

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients.
Affected versions:
Spring AI: 2.0.0

相关链接

相关漏洞

« 返回首页