An attacker who can publish to a queue consumed by an...
Moderate severity
Unreviewed
Published
Aug 27, 2026
to the GitHub Advisory Database
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Aug 27, 2026
Published to the GitHub Advisory Database
Aug 27, 2026
Last updated
Sep 2, 2026
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier
References