Intel

AIKIDO-2026-11162

spring-websocket is vulnerable to Predictable Session IDs

Predictable Session IDsCVE-2026-41838 Published Yesterday

48

Medium Risk

This Affects:

JAVAspring-websocket
5.3.0 - 5.3.48
Fixed in 5.3.49
6.1.0 - 6.1.27
Fixed in 6.1.28
6.2.0 - 6.2.18
Fixed in 6.2.19
7.0.0 - 7.0.7
Fixed in 7.0.7.1
Are you affected? Scan for Free

TL;DR

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-websocket is vulnerable to Predictable Session IDs in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7.

How to fix this

Upgrade the org.springframework:spring-websocket library to the patch version.