CVE-2026-47860: VMware Spring Advanced Message Queuing Protocol
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Affected products
- VMware Spring Advanced Message Queuing Protocol: before 2.4.19 (fixed in 2.4.19); from 3.2.0, before 3.2.13 (fixed in 3.2.13); from 4.0.0, before 4.0.4.1 (fixed in 4.0.4.1); from 4.1.0, before 4.1.0.1 (fixed in 4.1.0.1)
Published 2026-08-27. Last modified 2026-09-02.