CVE-2026-59271
Last modified
CVE-2026-59271 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Advanced Message Queuing Protocol | < 2.4.19 |
| Vmware | Spring Advanced Message Queuing Protocol | >= 3.2.0, < 3.2.13 |
| Vmware | Spring Advanced Message Queuing Protocol | >= 4.0.0, < 4.0.4.1 |
| Vmware | Spring Advanced Message Queuing Protocol | >= 4.1.0, < 4.1.0.1 |
References
- https://spring.io/security/cve-2026-59271Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59271?
How severe is CVE-2026-59271?
How do I fix CVE-2026-59271?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5926IBM Verify Identity Access Container 11.0 through 11.0.2 and…6.5
- CVE-2026-59260OpenWrt luci-app-samba4 read ACL grants file.exec permission…8.8
- CVE-2026-59261OpenClaw before 2026.5.28 contains a credential exposure vul…6.5
- CVE-2026-59262AFFiNE's histories GraphQL field fails to validate Doc.Read …6.5
- CVE-2026-59269A user authenticating to Kubernetes clusters via the Pinnipe…3.8
- CVE-2026-59270Spring Security's embedded UnboundID LDAP server (UnboundIdC…9.1
- CVE-2026-59272Any application shipping logs to RabbitMQ over TLS via the L…6.8
- CVE-2026-59274The UnZipTransformer does not limit decompressed entry size …6.5
- CVE-2026-59275A single hostile AMQP message can terminate the entire consu…4.9
- CVE-2026-59276Several components in Spring Security compare security-sensi…5.9
- CVE-2026-59277Spring Security's InetAddressMatchers utility provides match…5.3
- CVE-2026-59278JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include j…6.5
Are you affected by CVE-2026-59271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
