Improper Certificate Validation in Spring AMQP - CVE-2026-59272

 

Improper Certificate Validation in Spring AMQP - CVE-2026-59272

Published: August 28, 2026


Vulnerability identifier: #VU146202
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59272
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read or alter log traffic.

The vulnerability exists due to improper certificate validation in the Log4j2 AmqpAppender when shipping logs to RabbitMQ over TLS. A remote user can perform a man-in-the-middle attack on the network path to read or alter log traffic.

The issue affects deployments relying on the documented default behavior for hostname verification.


Affected software

Spring AMQP

How to mitigate CVE-2026-59272

Install security update from vendor's website.

Spring AMQP - addressed in versions 2.4.19, 3.2.13, 4.0.4.1, 4.0.5, 4.1.0.1, 4.1.1

External References

Related Security Bulletins