Skip to main content

Use of Insufficiently Random Values

CVE-2026-41701

Severity Medium
Score 4.4/10

Summary

Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP through 3.2.10, 4.0.x through 4.0.3; 4.1.x through 4.1.0-RC1.

  • HIGH
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • HIGH
  • LOW
  • NONE

CWE-330 - Use of Insufficiently Random Values

The software uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Advisory Timeline

  • Published