spring-ai-redis-semantic-cache is vulnerable to Use of Weak Hash
42
Medium Risk
spring-ai-redis-semantic-cache isolates cached responses with a truncated SHA-256 of the system prompt. Distinct prompts can then collide and share cached replies across tenants or contexts. A caller can receive an answer generated under a different prompt. The patch uses a collision-resistant context key that is not truncated into a shared bucket.
You are affected if you are using a version that falls within the vulnerable range and Spring AI Redis semantic cache isolates entries by truncated SHA-256 context hashes.
spring-ai-redis-semantic-cache is vulnerable to Use of Weak Hash in versions 2.0.0 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-redis-semantic-cache library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant