Vmware Spring Advanced Message Queuing Protocol — known CVE vulnerabilities
Every CVE whose affected-product data names Vmware Spring Advanced Message Queuing Protocol, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2016-2173 — CVSS 9.8 (critical): org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
CVE-2026-59272 — CVSS 6.8 (medium): Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to…
CVE-2026-59275 — CVSS 6.6 (medium): A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability…
CVE-2026-47860 — CVSS 6.5 (medium): An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a…
CVE-2026-59320 — CVSS 6.5 (medium): When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still…
CVE-2021-22095 — CVSS 6.5 (medium): In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new…
CVE-2021-22097 — CVSS 6.5 (medium): In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a…
CVE-2026-59271 — CVSS 5.3 (medium): When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message…
CVE-2023-34050 — CVSS 5.0 (medium): In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring…
CVE-2026-41701 — CVSS 4.4 (medium): Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple…
CVE-2026-41714 — CVSS 4.0 (medium): Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling…