CVE-2026-59271

Source
https://cve.org/CVERecord?id=CVE-2026-59271
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59271.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59271
Published
2026-08-27T05:20:34Z
Modified
2026-09-03T03:48:20Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Admin password disclosed in BrokerNotAliveException message
Details

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59271.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.1.0"
                },
                {
                    "last_affected": "4.1.0"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.0.4"
                },
                {
                    "introduced": "3.2.0"
                },
                {
                    "last_affected": "3.2.12"
                },
                {
                    "last_affected": "2.4.18"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-amqp

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-amqp
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.1.0"
        },
        {
            "fixed": "4.1.0.1"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59271.json"