Spring Amqp vulnerabilities
3 known vulnerabilities affecting spring/spring_amqp.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-34050P4MEDIUMCVSS 4.3≥ 1.0.0, < 2.4.17≥ 3.0.0, < 3.0.102023-10-19
CVE-2023-34050 [MEDIUM] CWE-502 CVE-2023-34050: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for des
In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes could be deserialized.
Specifically, an application is
vulnerab
nvd
CVE-2026-41701P4MEDIUMCVSS 4.4≥ 4.0.0, < 4.0.3.1≥ 3.2.0, < 3.2.10.1+2 more2026-06-10
CVE-2026-41701 [MEDIUM] CWE-330 CVE-2026-41701: Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are pr
Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd
CVE-2026-41714P4MEDIUMCVSS 4.0≥ 4.0.0, < 4.0.3.1≥ 3.2.0, < 3.2.10.1+2 more2026-06-10
CVE-2026-41714 [MEDIUM] CWE-295 CVE-2026-41714: Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd