Vmware · Spring Amqp · CVE-2026-47860
**Name of the Vulnerable Software and Affected Versions**
Spring AMQP version 4.1.0
Spring AMQP versions 4.0.0 through 4.0.4
Spring AMQP versions 3.2.0 through 3.2.12
Spring AMQP versions 2.4.18 and earlier
**Description**
An attacker capable of publishing to a queue consumed by an application with message decompression enabled can cause the consumer JVM (Java Virtual Machine) to crash by sending a single message of approximately 1 MB. This occurs due to unbounded decompression of attacker-supplied compressed message bodies.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.