cbcvebase.
CVE-2026-59272
published 2026-08-27

CVE-2026-59272: Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of…

PriorityP336medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
0.16%
5.8th percentile
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianceph
offline-knowledge-portalrhokp-rhel9
pki-core_10.6resteasy
pki-deps_10.6resteasy
redhatresteasy
rhai-early-accessdocling-serve-cuda-rhel9
rhaiivllm-gaudi-rhel9
rhaiisvllm-cuda-rhel9
rhelai3bootc-gaudi-rhel9
rhoaiodh-modelmesh-rhel9
rhoaiodh-pipeline-runtime-datascience-cpu-py312-rhel9
rhoaiodh-pipeline-runtime-pytorch-cuda-py312-rhel9
rhoaiodh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
rhoaiodh-pipeline-runtime-pytorch-rocm-py312-rhel9
rhoaiodh-pipeline-runtime-tensorflow-cuda-py312-rhel9
rhoaiodh-pipeline-runtime-tensorflow-rocm-py312-rhel9
rhoaiodh-spark-operator-rhel9
rhoaiodh-th-torch-cpu-py312-rhel9
rhoaiodh-th-torch-cuda-py312-rhel9
rhoaiodh-th06-cpu-torch210-py312-rhel9
rhoaiodh-th06-cpu-torch291-py312-rhel9
rhoaiodh-th06-cuda130-torch210-py312-rhel9
rhoaiodh-th06-cuda130-torch291-py312-rhel9
rhoaiodh-th06-rocm64-torch291-py312-rhel9
rhoaiodh-vllm-gaudi-rhel9

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.