Improper Resource Shutdown or Release in Spring AMQP - CVE-2026-59320
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in the listener container link credit handling when processing message deliveries that trigger exceptions while a container-level ErrorHandler is configured. A remote user can send messages that repeatedly cause listener processing failures to cause a denial of service.
Only deployments with a container-level ErrorHandler configured are vulnerable, and the listener may remain reported as running after message delivery has stalled.