CVE-2026-59320

MEDIUM CVSS 3.1: 6.5 EPSS 0.30%
Updated Aug 31, 2026
VMWARE
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions 4.1.0 — 4.1.1
Fixed In 4.1.1
Type CWE-772, CWE-772 Missing Release of Resource after Effective Lifetime
Vendor VMWARE
Public PoC No

When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently stalled while isRunning() remains true. Spring AMQP 4.1.0

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Vmware Spring_Advanced_Message_Queuing_Protocol
cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:*:*:*:*:*:*:*:*
4.1.0 4.1.1