{"id":"GHSA-r5pm-vrc5-3m73","summary":"cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions","details":"### Impact\n\nFor jobs with `shouldBeUnique = true` the queue plugin will generate a 'unique identifier' based on the job class, method and parameters. If user data is supplied, a malicious user could create collisions, resulting in legitimate jobs being dropped.\n\n### Patches\nUpgrade to 2.3.1\n\n### Workarounds\n\nYou can disable `shouldBeUnique` and handle idempotency in application code.","aliases":["CVE-2026-54713"],"modified":"2026-08-27T17:25:39.132650Z","published":"2026-08-27T17:03:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-27T17:03:56Z","nvd_published_at":null,"cwe_ids":["CWE-1023"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/cakephp/queue/security/advisories/GHSA-r5pm-vrc5-3m73"},{"type":"WEB","url":"https://github.com/cakephp/queue/pull/188"},{"type":"WEB","url":"https://github.com/cakephp/queue/commit/13890591e248acc8824becb24ba1939fa061bd34"},{"type":"PACKAGE","url":"https://github.com/cakephp/queue"},{"type":"WEB","url":"https://github.com/cakephp/queue/releases/tag/2.3.1"}],"affected":[{"package":{"name":"cakephp/queue","ecosystem":"Packagist","purl":"pkg:composer/cakephp/queue"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.1.10"},{"fixed":"2.3.1"}]}],"versions":["0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","1.0.0","1.1.0","2.0.1","2.1.0","2.2.0","2.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-r5pm-vrc5-3m73/GHSA-r5pm-vrc5-3m73.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}