Improper Certificate Validation in Spring AMQP - CVE-2026-59272
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to read or alter log traffic.
The vulnerability exists due to improper certificate validation in the Log4j2 AmqpAppender when shipping logs to RabbitMQ over TLS. A remote user can perform a man-in-the-middle attack on the network path to read or alter log traffic.
The issue affects deployments relying on the documented default behavior for hostname verification.