spring-amqp is vulnerable to Denial of Service (DoS)
65
Medium Risk
spring-amqp decompresses attacker-supplied compressed message bodies without a bound. A single roughly 1 MB compressed message can crash the consumer JVM with OutOfMemoryError. The default JavaLangErrorHandler then calls System.exit(99), and redelivery can crash-loop the service. The patch limits decompression so a compressed body cannot exhaust the heap.
You are affected if you are using a version that falls within the vulnerable range and message decompression is enabled on a consumed AMQP queue.
spring-amqp is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 4.0.4 and 4.1.0 - 4.1.0.
Upgrade the org.springframework.amqp:spring-amqp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant