CVE-2026-54713
CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting parameter values drops associative-array keys. An unauthenticated attacker who can influence job parameters can submit semantically different data that produces the same identifier, resulting in legitimate jobs dropped as duplicate collisions. This issue is fixed in version 2.3.1.
Scoring
- Severity
- LOW
- CVSS base score
- 3.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.36%
- CWE
- CWE-1023
- Published
- 2026-08-27
- Last modified
- 2026-08-28
Affected products
- cakephp queue
Weakness type
Related vulnerabilities
- CVE-2026-81376 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-14199 — Session takeover via Auth Proxy cache key collision
- CVE-2026-24255 — NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an...
- CVE-2026-48761 — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
- CVE-2026-53859 — OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
- CVE-2026-53839 — OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
- CVE-2026-7473 — Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
- CVE-2026-48587 — Potential exposure of private data via whitespace padding in Vary header