Man-in-the-Middle Vulnerability in Spring AMQP Products by Pivotal Software
CVE-2026-59272
6.8MEDIUM
What is CVE-2026-59272?
Applications utilizing the Log4j2 appender to send logs to RabbitMQ over TLS are susceptible to man-in-the-middle attacks. This vulnerability arises when the documented default configuration is used, enabling attackers to intercept and potentially manipulate every log event transmitted. This poses a significant risk to the integrity and confidentiality of the application's logging process.
Affected Version(s)
Spring AMQP 4.1.0
Spring AMQP 4.0.0 <= 4.0.4
Spring AMQP 3.2.0 <= 3.2.12
