Intel

AIKIDO-2026-855688

mcp-spring-webflux is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-59279 Published Aug 21, 2026

75

High Risk

This Affects:

JAVAmcp-spring-webflux
2.0.0 - 2.0.0
Fixed in 2.0.1
Are you affected? Scan for Free

TL;DR

mcp-spring-webflux and mcp-spring-webmvc retain MCP Streamable HTTP sessions with no cap, and authentication is not required by default. A remote client can create sessions until memory is exhausted. Legitimate clients then lose the service. The patch bounds the number of retained sessions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the MCP Streamable HTTP server transport is exposed without authentication.

Background info

mcp-spring-webflux is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.0.0.

How to fix this

Upgrade the org.springframework.ai:mcp-spring-webflux and/or the org.springframework.ai:mcp-spring-webmvc library to the patch version.