CVE-2026-59272
published 2026-08-27CVE-2026-59272: Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of…
PriorityP336medium6.8CVSS 3.1
AVNACHPRLUINSUCHIHAN
EPSS
0.16%
5.8th percentile
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | — | — |
| offline-knowledge-portal | rhokp-rhel9 | — | — |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
| rhai-early-access | docling-serve-cuda-rhel9 | — | — |
| rhaii | vllm-gaudi-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhelai3 | bootc-gaudi-rhel9 | — | — |
| rhoai | odh-modelmesh-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-spark-operator-rhel9 | — | — |
| rhoai | odh-th-torch-cpu-py312-rhel9 | — | — |
| rhoai | odh-th-torch-cuda-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-vllm-gaudi-rhel9 | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Spring AMQP up to 2.4.18/3.2.12/4.0.4/4.1.0 certificate host validation (EUVD-2026-67093)
vuldb·2026-08-27·CVSS 6.8
CVE-2026-59272 [MEDIUM] VMware Spring AMQP up to 2.4.18/3.2.12/4.0.4/4.1.0 certificate host validation (EUVD-2026-67093)
A vulnerability was found in VMware Spring AMQP up to 2.4.18/3.2.12/4.0.4/4.1.0. It has been rated as problematic. Affected is an unknown function. The manipulation leads to certificate with host mismatch.
This vulnerability is listed as CVE-2026-59272. The attack may be initiated remotely. There is no available exploit.
GHSA
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
ghsa_unreviewed·2026-08-27
CVE-2026-59272 [MEDIUM] CWE-297 Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Red Hat
org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
vendor_redhat·2026-08-27·CVSS 6.8
CVE-2026-59272 [MEDIUM] CWE-295 org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
A flaw was found in the Log4j2 AMQP Appender. When configured to ship logs to RabbitMQ over Transport Layer Security (TLS), the appender disables hostname verification by default. This misconfiguration allows a remote attacker to perform a man-in-the-middle (MITM) attack, intercepting sensitive log events. This can lead to unauthorized information disclosu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59272 ceph: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
bugzilla·2026-09-03·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 ceph: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
CVE-2026-59272 ceph: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Bugzilla
CVE-2026-59272 cldr-emoji-annotation: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
bugzilla·2026-09-03·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 cldr-emoji-annotation: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
CVE-2026-59272 cldr-emoji-annotation: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Bugzilla
CVE-2026-59272 resteasy: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
bugzilla·2026-09-03·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 resteasy: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
CVE-2026-59272 resteasy: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Bugzilla
CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [epel-all]
bugzilla·2026-09-03·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [epel-all]
CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Bugzilla
CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
bugzilla·2026-09-03·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
CVE-2026-59272 flexmark-java: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
Bugzilla
CVE-2026-59272 org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
bugzilla·2026-08-27·CVSS 6.8
CVE-2026-59272 [MEDIUM] CVE-2026-59272 org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
CVE-2026-59272 org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
2026-08-27
Published