Junglewise Threat Intelligence

CVE-2026-59320: Spring AMQP link credit exhaustion in error handler

CVE-2026-59320 · Severity: medium · CVSS 6.5 · Published 2026-08-27

Technologies: Spring AMQP. Vendors: Spring, VMware.

Executive brief

Spring AMQP is a messaging library used by Java applications to communicate over AMQP brokers like RabbitMQ. When an error handler is configured, failed message deliveries permanently consume link credits; after exhaustion, the broker stops delivering messages, leaving the listener silently stalled even though the application reports it is still running. This causes message processing to hang indefinitely without clear indication of the problem.

Technical details

Spring AMQP 4.1.0 contains a resource exhaustion vulnerability in its container-level error handler. When a delivery fails and an error handler is configured (a mitigation for CVE-2026-50000), the framework does not properly restore link credits to the broker, causing each failed message to permanently consume one credit. After the default 100 initial credits are exhausted, the receiver's credit reaches zero and the broker halts delivery, leaving the listener in a stalled state while isRunning() incorrectly reports true. The attack vector is network-adjacent (requires broker connectivity) and no authentication bypass is involved; an attacker with access to send messages to the target broker can trigger failures via malformed or intentionally failing messages.

Affected products

  • Spring AMQP 4.1.0

Timeline

  • 2026-08-27: disclosed

References

Related threats