Spring AMQP

5 known vulnerabilities in Spring AMQP, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-59320 CVSS 6.5 medium When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still…
  • CVE-2026-59272 CVSS 6.8 medium Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to…
  • CVE-2026-59275 CVSS 4.9 medium A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability…
  • CVE-2026-59271 CVSS 6.5 medium When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception…
  • CVE-2026-47860 CVSS 6.5 medium An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a…