Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-40971

Spring Boot: RabbitMQ auto-configuration with an SSL bundle does not verify the broker hostname

Technology

Spring Boot

CVSS Score

9.1 / 10.0

Affected Versions

4.0.0 to 4.0.5; 3.5.0 to 3.5.13

Upstream Fix

4.0.6; 3.5.14

Published

April 27, 2026

OSSeva Coverage

Fixed upstream

Description

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. NVD scores the record 9.1; VMware, as the CNA, scores it 5.0. Fixed in 4.0.6 and 3.5.14.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13, you need this patch. Book a discovery call to get covered.