VendorsVMwarespring_advanced_message_queuing_protocolall versions
Vulnerabilities

VMware Spring Advanced Message Queuing Protocol (AMQP)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2016-2173
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
Published 2017-04-21 · Modified
9.8EPSS 0.063
CVE-2021-22097
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the application if the toString() method is called.
Published 2021-10-28 · Modified
6.8EPSS 0.011
CVE-2026-59272
Log4j2 AmqpAppender disables TLS hostname verification by default
Published 2026-08-27 · Analyzed
6.8EPSS 0.002
CVE-2026-59275
Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99)
Published 2026-08-27 · Analyzed
6.6EPSS 0.002
CVE-2021-22095
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message
Published 2021-11-30 · Modified
6.5EPSS 0.011
CVE-2026-59271
Admin password disclosed in BrokerNotAliveException message
Published 2026-08-27 · Analyzed
6.5EPSS 0.003
CVE-2026-59320
In Spring AMQP the link credit never replenished on listener exception path
Published 2026-08-27 · Analyzed
6.5EPSS 0.003
CVE-2026-47860
Unbounded decompression of attacker-supplied compressed message bodies
Published 2026-08-26 · Analyzed
6.5EPSS 0.002
CVE-2023-34050
Spring AMQP Deserialization Vulnerability
Published 2023-10-19 · Modified
5.0EPSS 0.015
CVE-2026-41714
In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager
Published 2026-06-09 · Analyzed
4.0EPSS 0.001