Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.amqp/spring-amqp
  4. ›
  5. CVE-2026-41714

CVE-2026-41714: Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean

June 10, 2026 (updated August 12, 2026)

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri(“amqps://…”) without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.

Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

References

  • github.com/advisories/GHSA-p8qj-fj6r-w7q9
  • github.com/spring-projects/spring-amqp/releases/tag/v3.2.11
  • github.com/spring-projects/spring-amqp/releases/tag/v4.0.4
  • nvd.nist.gov/vuln/detail/CVE-2026-41714
  • spring.io/security/cve-2026-41714

Code Behaviors & Features

Detect and mitigate CVE-2026-41714 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.4.17, all versions starting from 3.1.0 up to 3.1.15, all versions starting from 3.2.0 before 3.2.11, all versions starting from 4.0.0 before 4.0.4

Fixed versions

  • 3.2.11
  • 4.0.4

Solution

Upgrade to versions 3.2.11, 4.0.4 or above.

Impact 4 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-295: Improper Certificate Validation

Source file

maven/org.springframework.amqp/spring-amqp/CVE-2026-41714.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:20:23 +0000.