CVE-2026-59272

Summary

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringSpring AMQP4.1.0affected
SpringSpring AMQP4.0.0 <= 4.0.4affected
SpringSpring AMQP3.2.0 <= 3.2.12affected
SpringSpring AMQP0 <= 2.4.18affected

Weaknesses

  • CWE-297 Improper Validation of Certificate with Host Mismatch

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References