CVE-2026-59275

Summary

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringSpring AMQP4.1.0affected
SpringSpring AMQP4.0.0 <= 4.0.4affected
SpringSpring AMQP3.2.0 <= 3.2.12affected
SpringSpring AMQP0 <= 2.4.18affected

Weaknesses

  • CWE-502 Deserialization of Untrusted Data

References