Allocation of Resources Without Limits or Throttling Affecting org.springframework.amqp:spring-amqp package, versions [,4.0.5)[4.1.0,4.1.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKAMQP-19268121
  • published26 Aug 2026
  • disclosed20 Aug 2026
  • creditRong Sun

Introduced: 20 Aug 2026

NewCVE-2026-47860  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade org.springframework.amqp:spring-amqp to version 4.0.5, 4.1.1 or higher.

Overview

org.springframework.amqp:spring-amqp is a package that provides support for using Spring and Java with AMQP 0.9.1, and in particular RabbitMQ.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via message decompression. An attacker can cause the consumer JVM to crash and potentially trigger a crash loop by sending a specially crafted compressed message to a queue consumed by an application with message decompression enabled.

Note: This is only exploitable if message decompression is enabled and the attacker can publish to the relevant queue.

CVSS Base Scores

version 4.0
version 3.1