Intel

AIKIDO-2026-10585

spring-boot-rabbitmq is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-40971 Published Apr 27, 2026

50

Medium Risk

This Affects:

JAVAspring-boot-rabbitmq
3.5.0 - 3.5.13
Fixed in 3.5.14
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper validation of certificate hostnames in RabbitMQ auto-configuration when using an SSL bundle, causing TLS connections to trust certificates without verifying they match the intended broker hostname. This can enable machine-in-the-middle attacks against RabbitMQ traffic.

Who does this affect?

You are affected if using a vulnerable version and you are connecting to RabbitMQ.

Background info

spring-boot-rabbitmq is vulnerable to Improper Certificate Validation in versions 3.5.0 - 3.5.13 and 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.boot:spring-boot-rabbitmq library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform