CVE-2026-59272 Any application shipping logs to RabbitMQ over TLS via… — CVE Notify — TG.ME

🚨 CVE-2026-59272
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier

🎖@cveNotify
Log4j2 AmqpAppender disables TLS hostname verification by default
Level up your Java code and explore what Spring can do for you.
September 1, 2026 36 1