Spring / Spring Amqp
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59320 | In Spring AMQP the link credit never replenished on listener exception path | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-59272 | Log4j2 AmqpAppender disables TLS hostname verification by default | MEDIUM | 6.8 | Aug 27, 2026 |
| CVE-2026-59275 | Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99) | MEDIUM | 6.6 | Aug 27, 2026 |
| CVE-2026-59271 | Admin password disclosed in BrokerNotAliveException message | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-47860 | Unbounded decompression of attacker-supplied compressed message bodies | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-41701 | In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues | MEDIUM | 4.4 | Jun 10, 2026 |
| CVE-2026-41714 | In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager | MEDIUM | 5.9 | Jun 9, 2026 |
| CVE-2023-34050 | Spring AMQP Deserialization Vulnerability | MEDIUM | 5.0 | Oct 19, 2023 |
Showing 1 to 8 of 8 CVEs