CVE-2026-59272

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
References
Link Resource
https://spring.io/security/cve-2026-59272 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-27 17:18

Updated : 2026-09-01 15:50


NVD link : CVE-2026-59272

Mitre link : CVE-2026-59272

CVE.ORG link : CVE-2026-59272


JSON object : View

Products Affected

vmware

  • spring_advanced_message_queuing_protocol
CWE
CWE-297

Improper Validation of Certificate with Host Mismatch