springdoc-openapi-starter-webflux-mcp is vulnerable to Exposure of Data Element to Wrong Session
65
Medium Risk
The WebFlux MCP filter stores per request MCP context, including forwarded headers, in a ThreadLocal. Because Reactor event-loop threads are shared across concurrent requests, one request can read context captured for another, leaking authentication and session headers into a different caller's downstream requests. This produces a confused-deputy cross-request disclosure under concurrency. The patch isolates the context to the reactive request scope instead of a ThreadLocal.
You are affected if you are using a version that falls within the vulnerable range and you run the WebFlux MCP starter serving concurrent requests.
springdoc-openapi-starter-webflux-mcp is vulnerable to Exposure of Data Element to Wrong Session in versions 3.0.3 - 3.1.0.
Upgrade the springdoc-openapi-starter-webflux-mcp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.