Executive brief
Spring AMQP is a library used by Java applications to communicate with message brokers like RabbitMQ. A security issue exists where applications using specific configuration methods may establish encrypted connections without verifying the identity of the server. This could allow an attacker to intercept or view sensitive data transmitted between the application and the message broker.
Technical details
A vulnerability in Spring AMQP Core (CWE-295) exists within the RabbitConnectionFactoryBean component. When a developer configures a connection using a URI starting with 'amqps://' via the setUri() method, the library fails to perform mandatory TLS certificate validation and hostname verification unless setUseSSL(true) is explicitly called. This improper certificate validation allows for potential man-in-the-middle (MITM) attacks where an attacker could intercept encrypted traffic. The issue is resolved in versions 4.0.4 and 3.2.11; users on older branches should upgrade to a supported version.
Affected products
- Spring Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17
Timeline
- 2026-06-09: disclosed
- 2026-06-10: advisory