CVE-2026-47860: Unbounded decompression of attacker-supplied compressed message bodies

Published Aug 26, 2026
·
Updated

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected Software

4 affected components
Spring Spring AMQP=4.1.0
Spring Spring AMQP>=4.0.0<4.0.5
Spring Spring AMQP>=3.2.0<=3.2.12
Spring Spring AMQP<=2.4.18

Event History

Aug 26, 2026
CVE Published
via MITRE·11:28 PM
Data Sourced
via MITRE·11:28 PM
DescriptionSeverityWeakness
Aug 27, 2026
Data Sourced
via NVD·01:17 AM
DescriptionSeverity

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Applications using Spring AMQP are exposed when they consume from a queue, have message decompression enabled, and an attacker can publish messages to that queue. The issue affects Spring AMQP 4.1.0, 4.0.0 through 4.0.4, 3.2.0 through 3.2.12, and 2.4.18 and earlier.

2

What level of access does an attacker need?

The attacker needs privileges to publish to a queue consumed by the target application. No user interaction is required, and a single attacker-supplied compressed message of approximately 1 MB can crash the consumer JVM.

3

Are applications using the default configuration affected?

The provided information identifies message decompression as a required condition. It does not state whether message decompression is enabled by default.

4

What can be done if an upgrade cannot be applied immediately?

Disable message decompression where possible and restrict publishing permissions on queues consumed by affected applications. Prioritize queues to which untrusted or broadly privileged publishers have access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203