CVE-2026-59320
- EPSS 0.29%
- Veröffentlicht 27.08.2026 18:04:47
- Zuletzt bearbeitet 31.08.2026 17:19:34
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches...
CVE-2026-59272
- EPSS 0.16%
- Veröffentlicht 27.08.2026 16:41:08
- Zuletzt bearbeitet 01.09.2026 15:50:45
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spr...
CVE-2026-59275
- EPSS 0.25%
- Veröffentlicht 27.08.2026 06:17:22
- Zuletzt bearbeitet 01.09.2026 18:22:14
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 ...
CVE-2026-59271
- EPSS 0.3%
- Veröffentlicht 27.08.2026 06:17:21
- Zuletzt bearbeitet 01.09.2026 18:29:11
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
CVE-2026-47860
- EPSS 0.24%
- Veröffentlicht 26.08.2026 23:28:46
- Zuletzt bearbeitet 02.09.2026 16:37:03
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18...
- EPSS 0.13%
- Veröffentlicht 09.06.2026 23:48:16
- Zuletzt bearbeitet 23.07.2026 09:10:00
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring ...
CVE-2026-41701
- EPSS 0.17%
- Veröffentlicht 09.06.2026 23:47:54
- Zuletzt bearbeitet 01.10.2026 13:34:16
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 throu...
CVE-2023-34050
- EPSS 1.54%
- Veröffentlicht 19.10.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 08:06:28
In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by ...
CVE-2021-22095
- EPSS 1.02%
- Veröffentlicht 30.11.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:31
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
CVE-2021-22097
- EPSS 1.04%
- Veröffentlicht 28.10.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:31
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious...