CVE-2026-59272 - Log4j2 AmqpAppender disables TLS hostname verification by default
Brief
CVE ID : CVE-2026-59272
Published : Aug. 27, 2026, 4:41 p. m.
- 32 minutes ago
Description : Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event. Spring AMQP 4.
- 0 Spring AMQP 4.
- 0 - 4.
- 4 Spring AMQP 3.
- 0 - 3.
- 12 Spring AMQP 2.
- 18 and earlier
Severity: 6.8
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
