4.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
Description
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
Basic Information
ID
CVE-2026-41701
Source
vmware
Published
Jun 9, 2026 at 23:47
Affected Product
Vendor
Spring
Product
Spring AMQP
Version
4.0.0
Affected Versions
Spring Spring AMQP 4.0.0
Spring Spring AMQP 3.2.0
Spring Spring AMQP 3.1.0
Spring Spring AMQP 2.4.0
Spring Spring AMQP 3.2.0
Spring Spring AMQP 3.1.0
Spring Spring AMQP 2.4.0