Intel

AIKIDO-2026-11162

spring-websocket is vulnerable to Predictable Session IDs

Predictable Session IDsCVE-2026-41838 Published Jun 11, 2026

48

Medium Risk

This Affects:

JAVAspring-websocket
5.3.0 - 6.2.18
Fixed in 6.2.19
7.0.0 - 7.0.7
Fixed in 7.0.8
Are you affected? Scan for Free

TL;DR

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-websocket is vulnerable to Predictable Session IDs in versions 5.3.0 - 6.2.18 and 7.0.0 - 7.0.7.

How to fix this

Upgrade the org.springframework:spring-websocket library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform