cbcvebase.

Vmware Spring Advanced Message Queuing Protocol vulnerabilities

10 known vulnerabilities affecting vmware/spring_advanced_message_queuing_protocol.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM9

Vulnerabilities

Page 1 of 1
CVE-2016-2173P2CRITICALCVSS 9.8fixed in 1.5.52017-04-21
CVE-2016-2173 [CRITICAL] CWE-20 CVE-2016-2173: org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote at org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
nvd
CVE-2026-59271P3MEDIUMCVSS 6.5fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59271 [MEDIUM] CWE-209 CVE-2026-59271: When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cle When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
nvd
CVE-2026-59272P3MEDIUMCVSS 6.8fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59272 [MEDIUM] CWE-297 CVE-2026-59272: Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documente Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
nvd
CVE-2026-59320P3MEDIUMCVSS 6.5≥ 4.1.0, < 4.1.12026-08-27
CVE-2026-59320 [MEDIUM] CWE-772 CVE-2026-59320: When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remain
nvd
CVE-2026-47860P4MEDIUMCVSS 6.5fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-47860 [MEDIUM] CWE-835 CVE-2026-47860: An attacker who can publish to a queue consumed by an application that has enabled message decompres An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
nvd
CVE-2021-22097P4MEDIUMCVSS 6.5≥ 2.2.0, ≤ 2.2.18≥ 2.3.0, ≤ 2.3.102021-10-28
CVE-2021-22097 [MEDIUM] CWE-502 CVE-2021-22097: In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its to In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() metho
nvd
CVE-2021-22095P4MEDIUMCVSS 6.5≥ 2.2.0, < 2.2.19≥ 2.3.0, < 2.3.112021-11-30
CVE-2021-22095 [MEDIUM] CWE-502 CVE-2021-22095: In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its to In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
nvd
CVE-2026-59275P4MEDIUMCVSS 4.9fixed in 2.4.19≥ 3.2.0, < 3.2.13+2 more2026-08-27
CVE-2026-59275 [MEDIUM] CWE-502 CVE-2026-59275: A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
nvd
CVE-2023-34050P4MEDIUMCVSS 4.3≥ 1.0.0, < 2.4.16≥ 3.0.0, < 3.0.92023-10-19
CVE-2023-34050 [MEDIUM] CWE-502 CVE-2023-34050: In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for des In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized. Specifically, an application is vulnerab
nvd
CVE-2026-41714P4MEDIUMCVSS 4.0fixed in 2.4.18≥ 3.1.0, < 3.1.16+2 more2026-06-10
CVE-2026-41714 [MEDIUM] CWE-295 CVE-2026-41714: Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps:// Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
nvd
Vmware Spring Advanced Message Queuing Protocol vulnerabilities | cvebase