Vmware Spring Advanced Message Queuing Protocol vulnerabilities
10 known vulnerabilities affecting vmware/spring_advanced_message_queuing_protocol.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM9
Vulnerabilities
Page 1 of 1
CVE-2016-2173P2CRITICALCVSS 9.8fixed in 1.5.52017-04-21
CVE-2016-2173 [CRITICAL] CWE-20 CVE-2016-2173: org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote at
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
nvd
CVE-2026-59271P3MEDIUMCVSS 6.5fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59271 [MEDIUM] CWE-209 CVE-2026-59271: When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cle
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
nvd
CVE-2026-59272P3MEDIUMCVSS 6.8fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59272 [MEDIUM] CWE-297 CVE-2026-59272: Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documente
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
nvd
CVE-2026-59320P3MEDIUMCVSS 6.5≥ 4.1.0, < 4.1.12026-08-27
CVE-2026-59320 [MEDIUM] CWE-772 CVE-2026-59320: When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remain
nvd
CVE-2026-47860P4MEDIUMCVSS 6.5fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-47860 [MEDIUM] CWE-835 CVE-2026-47860: An attacker who can publish to a queue consumed by an application that has enabled message decompres
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
nvd
CVE-2021-22097P4MEDIUMCVSS 6.5≥ 2.2.0, ≤ 2.2.18≥ 2.3.0, ≤ 2.3.102021-10-28
CVE-2021-22097 [MEDIUM] CWE-502 CVE-2021-22097: In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its to
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() metho
nvd
CVE-2021-22095P4MEDIUMCVSS 6.5≥ 2.2.0, < 2.2.19≥ 2.3.0, < 2.3.112021-11-30
CVE-2021-22095 [MEDIUM] CWE-502 CVE-2021-22095: In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its to
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
nvd
CVE-2026-59275P4MEDIUMCVSS 4.9fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59275 [MEDIUM] CWE-502 CVE-2026-59275: A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
nvd
CVE-2023-34050P4MEDIUMCVSS 4.3≥ 1.0.0, < 2.4.16≥ 3.0.0, < 3.0.92023-10-19
CVE-2023-34050 [MEDIUM] CWE-502 CVE-2023-34050: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for des
In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class
names were added to Spring AMQP, allowing users to lock down deserialization of
data in messages from untrusted sources; however by default, when no allowed
list was provided, all classes could be deserialized.
Specifically, an application is
vulnerab
nvd
CVE-2026-41714P4MEDIUMCVSS 4.0fixed in 2.4.18≥ 3.1.0, < 3.1.16+2 more2026-06-10
CVE-2026-41714 [MEDIUM] CWE-295 CVE-2026-41714: Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.
Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd