System Termination Vulnerability in Spring AMQP by Pivotal Software
CVE-2026-59275

6.6MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59275?

A vulnerability in the Spring AMQP library allows a malicious AMQP message to cause the Java Virtual Machine (JVM) running the consumer to terminate unexpectedly. This results in a complete loss of availability for all workloads that share the same process, affecting the reliability and stability of applications. The vulnerability has been identified in multiple versions of Spring AMQP, and it is essential for users to upgrade to secure versions to mitigate the risks associated with this flaw.

Affected Version(s)

Spring AMQP 4.1.0

Spring AMQP 4.0.0 <= 4.0.4

Spring AMQP 3.2.0 <= 3.2.12

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.