SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59275

MEDIUM · CVSS 6.6 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in specific versions of Spring AMQP allows a malicious AMQP message to terminate the entire consumer JVM, resulting in a complete loss of availability for all workloads running in that process. This issue poses a risk to applications relying on Spring AMQP for message handling, particularly those in production environments. Organizations using affected versions should prioritize remediation to prevent potential service disruptions.

CVE
CVE-2026-59275
Severity
MEDIUM
CVSS
6.6
EPSS
0.25%

Original NVD Description

A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)