Generation of Predictable Numbers or Identifiers in Spring Framework - CVE-2026-41838

 

Generation of Predictable Numbers or Identifiers in Spring Framework - CVE-2026-41838

Published: August 28, 2026


Vulnerability identifier: #VU146167
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41838
CWE-ID: CWE-340
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to the use of predictable session identifiers in the spring-websocket module when establishing WebSocket sessions. A remote user can predict session IDs to disclose sensitive information.

Exploitation may be possible in combination with inadequate authorization rules, and user interaction is required.


Affected software

Spring Framework

How to mitigate CVE-2026-41838

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.49, 6.1.28, 6.2.18.1, 6.2.19, 7.0.7.1, 7.0.8

External References

Related Security Bulletins