CVE-2026-40971
published 2026-04-27CVE-2026-40971: When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker…
PriorityP349critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.16%
5.3th percentile
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| log4j_2 | log4j | — | — |
| spring | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Boot up to 3.5.13/4.0.5 RabbitMQ Auto-configuration certificate validation
vuldb·2026-04-28·CVSS 5.0
CVE-2026-40971 [MEDIUM] Vmware Spring Boot up to 3.5.13/4.0.5 RabbitMQ Auto-configuration certificate validation
A vulnerability, which was classified as critical, was found in Vmware Spring Boot up to 3.5.13/4.0.5. This affects an unknown part of the component RabbitMQ Auto-configuration. Such manipulation leads to improper certificate validation.
This vulnerability is referenced as CVE-2026-40971. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
GHSA
Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
ghsa·2026-04-28
CVE-2026-40971 [MEDIUM] CWE-295 Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
Red Hat
Spring Boot: Spring Boot: Information disclosure and data tampering via missing hostname verification
vendor_redhat·2026-04-27·CVSS 5.0
CVE-2026-40971 [MEDIUM] CWE-295 Spring Boot: Spring Boot: Information disclosure and data tampering via missing hostname verification
Spring Boot: Spring Boot: Information disclosure and data tampering via missing hostname verification
A flaw was found in Spring Boot. When configured to use an SSL (Secure Sockets Layer) bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. This vulnerability could allow an attacker on the same network to intercept or alter communications. The primary consequences include potential information disclosure and data tampering.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: spring-boot (Red Hat AMQ Broker 7) -
No detection rules found.
No public exploits indexed.
2026-04-27
Published