spring-amqp-client is vulnerable to Denial of Service (DoS)
65
Medium Risk
spring-amqp-client never replenishes link credit when a container-level ErrorHandler handles a listener exception. After the default 100 credits are consumed by failing deliveries, the broker stops sending while isRunning() remains true. The listener then stalls silently. The patch restores credit on the exception path.
You are affected if you are using a version that falls within the vulnerable range and a container-level ErrorHandler is configured on a Spring AMQP listener.
spring-amqp-client is vulnerable to Denial of Service (DoS) in versions 4.1.0 - 4.1.0.
Upgrade the org.springframework.amqp:spring-amqp-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant