GHSA-r5pm-vrc5-3m73LowCVSS 3.7

cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

For jobs with shouldBeUnique = true the queue plugin will generate a 'unique identifier' based on the job class, method and parameters. If user data is supplied, a malicious user could create collisions, resulting in legitimate jobs being dropped.

Patches

Upgrade to 2.3.1

Workarounds

You can disable shouldBeUnique and handle idempotency in application code.

🎯 Affected products1

  • composer/cakephp/queue:>= 0.1.10, < 2.3.1

🔗 References (5)