Generation of Predictable Numbers or Identifiers in Spring AMQP - CVE-2026-41701

 

Generation of Predictable Numbers or Identifiers in Spring AMQP - CVE-2026-41701

Published: August 28, 2026


Vulnerability identifier: #VU146177
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41701
CWE-ID: CWE-340
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject spoofed replies and disclose sensitive information.

The vulnerability exists due to improper generation of predictable identifiers in RabbitTemplate.sendAndReceive() with the fixed reply queue when processing reply correlation IDs. A remote privileged user can send a crafted reply with a predicted correlation ID to inject spoofed replies and disclose sensitive information.


Affected software

Spring AMQP

How to mitigate CVE-2026-41701

Install security update from vendor's website.

Spring AMQP - addressed in versions 2.4.18, 3.1.16, 3.2.10.1, 3.2.11, 4.0.3.1, 4.0.4

External References

Related Security Bulletins