VMware / Spring Advanced Message Queuing Protocol
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59320 | In Spring AMQP the link credit never replenished on listener exception path | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-59272 | Log4j2 AmqpAppender disables TLS hostname verification by default | MEDIUM | 6.8 | Aug 27, 2026 |
| CVE-2026-59275 | Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99) | MEDIUM | 6.6 | Aug 27, 2026 |
| CVE-2026-59271 | Admin password disclosed in BrokerNotAliveException message | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-47860 | Unbounded decompression of attacker-supplied compressed message bodies | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-41701 | In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues | MEDIUM | 4.4 | Jun 10, 2026 |
| CVE-2026-41714 | In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager | MEDIUM | 5.9 | Jun 9, 2026 |
| CVE-2023-34050 | Spring AMQP Deserialization Vulnerability | MEDIUM | 5.0 | Oct 19, 2023 |
| CVE-2021-22095 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the m… | MEDIUM | 6.5 | Nov 30, 2021 |
| CVE-2021-22097 | In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with… | MEDIUM | 6.5 | Oct 28, 2021 |
| CVE-2016-2173 | org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. | CRITICAL | 9.8 | Apr 21, 2017 |
Showing 1 to 11 of 11 CVEs