Predictable Correlation IDs in RabbitTemplate for Spring AMQP by Pivotal
CVE-2026-41701

4.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41701?

The vulnerability in Spring AMQP affects the RabbitTemplate's sendAndReceive() method where the correlation IDs for replies are generated using a predictable internal counter. This predictability can lead to security risks as attackers may exploit the predictable nature of correlation IDs, allowing them to manipulate message handling. The affected versions of Spring AMQP range from 2.4.0 to 4.0.3, and it is crucial for users to update their systems to mitigate the associated risks.

Affected Version(s)

Spring AMQP 4.0.0 < 4.0.3.1

Spring AMQP 3.2.0 < 3.2.10.1

Spring AMQP 3.1.0 < 3.1.16

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.