PT-2026-82416 · Vmware · Spring Amqp

CVE-2026-59275

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring AMQP version 4.1.0 Spring AMQP versions 4.0.0 through 4.0.4 Spring AMQP versions 3.2.0 through 3.2.12 Spring AMQP versions 2.4.18 and earlier
Description A single hostile AMQP message can cause the entire consumer JVM to terminate via a System.exit(99) call, resulting in a complete loss of availability for all workloads co-located within that process. This occurs because nested-array Java deserialization bypasses the allowlist, triggering a StackOverflowError, which then leads the default JavaLangErrorHandler to shut down the JVM.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59275

Affected Products

Spring Amqp