Vulnerability Description
The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a result, a remote attacker can cause the server to accumulate an unbounded number of sessions over time, gradually exhausting available memory and ultimately causing a Denial of Service that affects all legitimate clients. Affected versions: Spring AI: 2.0.0
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-59279?
CVE-2026-59279 is a vulnerability with a CVSS score of 7.5 (HIGH). The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated. As a ...
How severe is CVE-2026-59279?
CVE-2026-59279 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59279?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.