CVE-2026-41714Medium· 4.0▾ SunlitApplications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification. Affected vers…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.
Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.
spring_advanced_message_queuing_protocol < 2.4.18spring_advanced_message_queuing_protocol >= 3.1.0, < 3.1.16spring_advanced_message_queuing_protocol >= 3.2.0, < 3.2.10.1spring_advanced_message_queuing_protocol >= 4.0.0, < 4.0.3.1Upgrade past the affected range:
spring_advanced_message_queuing_protocol 4.0.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40992Medium· 5.0Spring Boot's Mail auto-configuration does not enable hostname verification
CVE-2021-20327Medium· 6.4A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate
CVE-2018-0227High· 7.5A vulnerability in the Secure Sockets Layer (SSL) Virtual Private Network (VPN) Client Certificate Authentication feature for Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to establish an SSL VPN…
CVE-2026-1531High· 8.1A flaw was found in foreman_kubevirt
CVE-2026-1530High· 8.1A flaw was found in fog-kubevirt
CVE-2026-33896High· 7.4Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript