CVE-2026-40971 PUBLISHED

Assigner: vmware
Reserved: 16.04.2026 Published: 27.04.2026 Updated: 27.04.2026

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 5

Product Status

Vendor Spring
Product Spring Boot
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.6 (excl.)
  • affected from 3.5.0 to 3.5.14 (excl.)

References

Problem Types

  • CWE-295: Improper Certificate Validation CWE

Impacts

  • Per CVSS v3.1: Confidentiality LOW; Integrity LOW; Availability LOW.