Executive brief
Spring Framework is a widely used software development framework for Java applications. A vulnerability in its WebSocket module means that session identifiers are generated in a predictable way rather than being truly random. If an application also has weak security rules, an attacker could potentially guess a user's session ID to gain unauthorized access to their data or communications.
Technical details
A vulnerability exists in the spring-websocket module of the Spring Framework where WebSocket session IDs are generated using a non-cryptographically secure method, leading to predictable values (CWE-330). An attacker with network access and low privileges could potentially predict session IDs, which, when combined with insufficient authorization checks, could lead to unauthorized access to session data. The vulnerability requires high attack complexity and user interaction according to the vendor's CVSS assessment. The issue has been addressed by switching to JdkIdGenerator for session ID generation. Patches are available in versions 7.0.8 and 6.2.19, with other branches requiring updates to their respective latest releases.
Affected products
- VMware Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
- 2026-07-29: patched
References
- https://spring.io/security/cve-2026-41838
- https://github.com/spring-projects/spring-framework/issues/36740
- https://github.com/spring-projects/spring-framework/commit/a42a6e0c6ac64eb18954729ca5e3fe64b05a39b5
- https://github.com/spring-projects/spring-framework/commit/bff98999056fc29b573ff47ad2433462eb52833c
- https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19