cbcvebase.

Spring Amqp vulnerabilities

3 known vulnerabilities affecting spring/spring_amqp.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-34050P4MEDIUMCVSS 4.3≥ 1.0.0, < 2.4.17≥ 3.0.0, < 3.0.102023-10-19
CVE-2023-34050 [MEDIUM] CWE-502 CVE-2023-34050: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for des In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized. Specifically, an application is vulnerab
nvd
CVE-2026-41701P4MEDIUMCVSS 4.4≥ 4.0.0, < 4.0.3.1≥ 3.2.0, < 3.2.10.1+2 more2026-06-10
CVE-2026-41701 [MEDIUM] CWE-330 CVE-2026-41701: Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are pr Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd
CVE-2026-41714P4MEDIUMCVSS 4.0≥ 4.0.0, < 4.0.3.1≥ 3.2.0, < 3.2.10.1+2 more2026-06-10
CVE-2026-41714 [MEDIUM] CWE-295 CVE-2026-41714: Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps:// Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd
Spring Amqp vulnerabilities | cvebase