Spring AI MCP Streamable HTTP server memory exhaustion DoS
The MCP Streamable HTTP server transport in Spring AI 2.0.0 does not limit session accumulation, allowing remote attackers to cause memory exhaustion and denial of service without authentication.
Disclosed 21 August 2026 · Record updated 13 September 2026
Impact
Remote attackers can exhaust server memory and cause denial of service affecting all legitimate clients by accumulating unbounded sessions without authentication.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59279
