CVE-2026-41838: Spring Framework Predictable Session ID in WebSocket Module
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41838?
The severity of CVE-2026-41838 is medium, with a score of 4.8.
What is CVE-2026-41838?
CVE-2026-41838 pertains to predictable session IDs in the Spring Framework's WebSocket module, leading to possible exploitation.
How do I fix CVE-2026-41838?
To fix CVE-2026-41838, upgrade your Spring Framework version to a patched release that addresses the predictable session ID issue.
What versions are affected by CVE-2026-41838?
CVE-2026-41838 affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.x.
Can CVE-2026-41838 lead to unauthorized access?
Yes, CVE-2026-41838 can lead to unauthorized access if combined with inadequate authorization rules.