Generation of Predictable Numbers or Identifiers in Spring Framework - CVE-2026-41838
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to the use of predictable session identifiers in the spring-websocket module when establishing WebSocket sessions. A remote user can predict session IDs to disclose sensitive information.
Exploitation may be possible in combination with inadequate authorization rules, and user interaction is required.