CVE-2026-59318: VMware Spring Ai
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9
Affected products
- VMware Spring Ai: from 1.0.0, before 1.0.10 (fixed in 1.0.10); from 1.1.0, before 1.1.9 (fixed in 1.1.9); from 2.0.0, before 2.0.1 (fixed in 2.0.1)
Published 2026-08-21. Last modified 2026-09-16.