CVE-2026-47860
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring AMQP | 4.1.0 | affected |
| Spring | Spring AMQP | 4.0.0 <= 4.0.4 | affected |
| Spring | Spring AMQP | 3.2.0 <= 3.2.12 | affected |
| Spring | Spring AMQP | 0 <= 2.4.18 | affected |
Weaknesses
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification, Decompression Bomb)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.