← Vulnerability feed

Vulnerability record · CVE-2026-59272 · published 27 August 2026

CVE-2026-59272: Vmware spring advanced message queuing protocol vulnerability

Vmware · Spring Advanced Message Queuing Protocol

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

6.8 CVSS 3.1 Medium EPSS 0.27% · top 83.0% CWE-297 · CWE-297
6.8CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
1 Sep 2026Last modified by NVD

Description

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-59272 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-2173Fedoraproject fedora improper input validation vulnerabilityorg.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.EPSS 6.3%6.5CVE-2026-59320Vmware spring advanced message queuing protocol vulnerabilityWhen a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consum…EPSS 0.42%6.5CVE-2026-59271Vmware spring advanced message queuing protocol error message information leak vulnerabilityWhen the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AM…EPSS 0.32%6.5CVE-2026-47860Vmware spring advanced message queuing protocol vulnerabilityAn attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 …EPSS 0.42%6.5CVE-2021-22095Vmware spring advanced message queuing protocol deserialization of untrusted data vulnerabilityIn Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object …EPSS 1.1%6.5CVE-2021-22097Vmware spring advanced message queuing protocol deserialization of untrusted data vulnerabilityIn Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a me…EPSS 1.1%4.9CVE-2026-59275Vmware spring advanced message queuing protocol deserialization of untrusted data vulnerabilityA single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for ever…EPSS 0.45%4.3CVE-2023-34050Vmware spring advanced message queuing protocol deserialization of untrusted data vulnerabilityIn spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2026-59272), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.