CVE-2026-59320: VMware Spring Advanced Message Queuing Protocol
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remains true. Spring AMQP 4.1.0
Affected products
- VMware Spring Advanced Message Queuing Protocol: from 4.1.0, before 4.1.1 (fixed in 4.1.1)
Published 2026-08-27. Last modified 2026-08-31.