{"id":"CVE-2026-41714","title":"Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri(\"amqps://...\") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.\n\nAffected vers…","summary":"Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri(\"amqps://...\") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.\n\nAffected vers…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-295"],"vendor":"vmware","product":"spring_advanced_message_queuing_protocol","affected":["spring_advanced_message_queuing_protocol < 2.4.18","spring_advanced_message_queuing_protocol >= 3.1.0, < 3.1.16","spring_advanced_message_queuing_protocol >= 3.2.0, < 3.2.10.1","spring_advanced_message_queuing_protocol >= 4.0.0, < 4.0.3.1"],"patched":["spring_advanced_message_queuing_protocol 4.0.3.1"],"published":"2026-06-10","updated":"2026-07-17","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41714","references":[{"url":"https://spring.io/security/cve-2026-41714","label":"security@vmware.com"}],"tags":["nvd"],"epss":0.00132,"epssPercentile":0.03153,"ingestedAt":"2026-07-17T21:16:24.169Z","slug":"CVE-2026-41714","body":"## Overview\n\nApplications that configure their broker connection via RabbitConnectionFactoryBean.setUri(\"amqps://...\") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.\n\nAffected versions:\nSpring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.\n\n## Affected\n\n- `spring_advanced_message_queuing_protocol < 2.4.18`\n- `spring_advanced_message_queuing_protocol >= 3.1.0, < 3.1.16`\n- `spring_advanced_message_queuing_protocol >= 3.2.0, < 3.2.10.1`\n- `spring_advanced_message_queuing_protocol >= 4.0.0, < 4.0.3.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_advanced_message_queuing_protocol 4.0.3.1`","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}