CVE-2026-59272CWE-297

CVE-2026-59272

Medium · published August 27, 2026

CVSS v3.1
6.8
EPSS
0%
Percentile
5.8
In the wild
Unconfirmed
What it is

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.

Spring AMQP 4.1.0

Spring AMQP 4.0.0 - 4.0.4

Spring AMQP 3.2.0 - 3.2.12

Spring AMQP 2.4.18 and earlier

The record
Technical detail
CVSS v3.1
6.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00163 · 5.8th percentile
Weakness
CWE-297 · Improper Validation of Certificate with Host Mismatch
Published
2026-08-27T21:18Z
Affected products (4)
ProductVersionsFixed in
vmware/spring_advanced_message_queuing_protocol< 2.4.192.4.19
vmware/spring_advanced_message_queuing_protocol≥ 3.2.0, < 3.2.133.2.13
vmware/spring_advanced_message_queuing_protocol≥ 4.0.0, < 4.0.4.14.0.4.1
vmware/spring_advanced_message_queuing_protocol≥ 4.1.0, < 4.1.0.14.1.0.1
References (1)
EPSS history
Timeline
  • 27 AUG 16:41Z
    Log4j2 AmqpAppender disables TLS hostname verification by default
    cvelistv5