{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-41701","assignerOrgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","state":"PUBLISHED","assignerShortName":"vmware","dateReserved":"2026-04-22T06:21:22.982Z","datePublished":"2026-06-09T23:47:54.996Z","dateUpdated":"2026-06-23T20:48:22.061Z"},"containers":{"cna":{"providerMetadata":{"orgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","shortName":"vmware","dateUpdated":"2026-06-23T20:48:22.061Z"},"title":"In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-330","description":"CWE-330: Use of Insufficiently Random Values","type":"CWE"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"An attacker who can inject messages into a fixed reply queue can predict sequential correlation IDs and poison replies, resulting in integrity or confidentiality impacts."}]}],"affected":[{"vendor":"Spring","product":"Spring AMQP","versions":[{"status":"affected","version":"4.0.0","lessThan":"4.0.3.1","versionType":"custom"},{"status":"affected","version":"3.2.0","lessThan":"3.2.10.1","versionType":"custom"},{"status":"affected","version":"3.1.0","lessThan":"3.1.16","versionType":"custom"},{"status":"affected","version":"2.4.0","lessThan":"2.4.18","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter.\n\nAffected versions:\nSpring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.","supportingMedia":[{"type":"text/html","base64":false,"value":"Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter.\n\nAffected versions:\nSpring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17."}]}],"references":[{"url":"https://spring.io/security/cve-2026-41701"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.4,"vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.1"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-10T13:04:42.963494Z","id":"CVE-2026-41701","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-10T13:04:52.283Z"}}]}}