WebSocket Session IDs Vulnerability in Spring Framework by Pivotal Software
CVE-2026-41838

4.8MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41838?

The Spring Framework has a vulnerability that arises from predictable IDs for WebSocket sessions within the spring-websocket module. This unpredictability can be exploited, especially when combined with insufficient authorization controls, potentially allowing unauthorized access to sensitive functionalities. Developers should ensure that their applications utilize secure session identifiers and enforce strict authorization policies to mitigate risks.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.