THREAT OPS › Threat News › [GHSA] GHSA-r5pm-vrc5-3m73 (low) — cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
[GHSA] GHSA-r5pm-vrc5-3m73 (low) — cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
GHSA-r5pm-vrc5-3m73 Severity: low CVE: CVE-2026-54713
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions
### Impact
For jobs with `shouldBeUnique = true` the queue plugin will generate a 'unique identifier' based on the job class, method and parameters. If user data is supplied, a malicious user could create collisions, resulting in legitimate jobs being dropped.
###
Indicators of compromise
- CVE-2026-54713cve
Original source: https://github.com/advisories/GHSA-r5pm-vrc5-3m73