CVE-2026-59275
6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring AMQP | 4.1.0 | affected |
| Spring | Spring AMQP | 4.0.0 <= 4.0.4 | affected |
| Spring | Spring AMQP | 3.2.0 <= 3.2.12 | affected |
| Spring | Spring AMQP | 0 <= 2.4.18 | affected |
Weaknesses
- CWE-502 Deserialization of Untrusted Data
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.