Generation of Predictable Numbers or Identifiers in Spring AMQP - CVE-2026-41701
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to inject spoofed replies and disclose sensitive information.
The vulnerability exists due to improper generation of predictable identifiers in RabbitTemplate.sendAndReceive() with the fixed reply queue when processing reply correlation IDs. A remote privileged user can send a crafted reply with a predicted correlation ID to inject spoofed replies and disclose sensitive information.