Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9vc8-qppq-wvxc | Spring Boot's RabbitMQ auto-configuration doesn't perform hostname verification when connecting to the RabbitMQ broker |
Thu, 14 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Boot |
|
| CPEs | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Boot |
Mon, 04 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hostname Verification Bypass in Spring Boot RabbitMQ SSL Connections | Spring Boot: Spring Boot: Information disclosure and data tampering via missing hostname verification |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hostname Verification Bypass in Spring Boot RabbitMQ SSL Connections | |
| Metrics |
ssvc
|
Tue, 28 Apr 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Boot |
|
| Vendors & Products |
Spring
Spring spring Boot |
Mon, 27 Apr 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-28T12:46:29.029Z
Reserved: 2026-04-16T02:18:56.133Z
Link: CVE-2026-40971
Updated: 2026-04-28T12:46:25.508Z
Status : Analyzed
Published: 2026-04-27T23:16:03.403
Modified: 2026-05-14T16:06:19.030
Link: CVE-2026-40971
OpenCVE Enrichment
Updated: 2026-04-28T13:00:15Z
Github GHSA