Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 31/8/2026 | When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently… | |
| Analizada | Media (6.8) | 0.27% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (4.9) | 0.45% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (6.5) | 0.32% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 1/9/2026 | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 2/9/2026 | An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier | |
| Analizada | Media (4) | 0.17% | — | Vmware Spring Advanced Message Queuing Protocol | 10/6/2026 | 23/7/2026 | Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15;… | |
| Analizada | Media (4.4) | 0.22% | — | Vmware Spring Advanced Message Queuing Protocol | 9/6/2026 | 1/10/2026 | Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to internal simple counter. Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17. | |
| Modificada | Media (4.3) | 1.5% | — | Vmware Spring Advanced Message Queuing Protocol | 19/10/2023 | 17/6/2026 | In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.… | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Advanced Message Queuing Protocol | 30/11/2021 | 17/6/2026 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message | |
| Modificada | Media (6.5) | 1.1% | — | Vmware Spring Advanced Message Queuing Protocol | 28/10/2021 | 17/6/2026 | In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object that can cause 100% CPU usage in the… | |
| Analizada | Media (5.9) | 1.2% | — | Pivotal Software Spring Advanced Message Queuing ProtocolVmware Rabbitmq Java Client | 14/9/2018 | 17/6/2026 | Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit. | |
| Modificada | Crítica (9.8) | 3.6% | — | Pivotal Software Spring Advanced Message Queuing Protocol | 27/11/2017 | 17/6/2026 | In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack. | |
| Modificada | Crítica (9.8) | 6.3% | — | Fedoraproject FedoraVmware Spring Advanced Message Queuing Protocol | 21/4/2017 | 17/6/2026 | org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code. |