Use of Insufficiently Random Values
CVE-2026-41701
Summary
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP through 3.2.10, 4.0.x through 4.0.3; 4.1.x through 4.1.0-RC1.
- HIGH
- NETWORK
- LOW
- CHANGED
- NONE
- HIGH
- LOW
- NONE
CWE-330 - Use of Insufficiently Random Values
The software uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Advisory Timeline
- Published