CVE-2026-41714: In Spring AMQP the RabbitConnectionFactoryBean.setUri("amqps://...") bypasses secure SSL setup, uses TrustEverythingTrustManager

Published Jun 9, 2026
·
Updated

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.

Affected versions: Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.1.0 through 3.1.15; 2.4.0 through 2.4.17.

Affected Software

5 affected components
Spring Spring AMQP>=4.0.0<=4.0.3, >=3.2.0<=3.2.10, >=3.1.0<=3.1.15, >=2.4.0<=2.4.17
VMware Spring Advanced Message Queuing Protocol<2.4.18
VMware Spring Advanced Message Queuing Protocol>=3.1.0<3.1.16
VMware Spring Advanced Message Queuing Protocol>=3.2.0<3.2.10.1
VMware Spring Advanced Message Queuing Protocol>=4.0.0<4.0.3.1

Event History

Jun 9, 2026
CVE Published
via MITRE·11:48 PM
Data Sourced
via MITRE·11:48 PM
DescriptionSeverityWeakness
Jun 10, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the risk associated with CVE-2026-41714?

The risk associated with CVE-2026-41714 is rated medium with a risk score of 22.

2

How does CVE-2026-41714 affect SSL setup in Spring AMQP?

CVE-2026-41714 allows RabbitConnectionFactoryBean.setUri("amqps://...") to bypass secure SSL setup, leading to potential TLS encryption without certificate validation.

3

What versions of Spring AMQP are affected by CVE-2026-41714?

Affected versions by CVE-2026-41714 include Spring AMQP 4.0.0 through 4.0.3, 3.2.0 through 3.2.10, and earlier versions.

4

How can I mitigate the vulnerability identified in CVE-2026-41714?

To mitigate CVE-2026-41714, ensure to call setUseSSL(true) when configuring the RabbitConnectionFactoryBean.

5

What is the consequence of using TrustEverythingTrustManager in CVE-2026-41714?

The use of TrustEverythingTrustManager in CVE-2026-41714 results in TLS encryption without any certificate validation or hostname verification.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203