Sploitus

CVE-2026-47860

No indexed exploits for CVE-2026-47860 yet

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected products
Spring Amqp
Vmware Spring Advanced Message Queuing Protocol
< 2.4.19, 3.2.13, 4.0.4.1, 4.1.0.1
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-835
NVD status
Analyzed
Published
2026-08-26
CVE-2026-47860 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-47860 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-47860 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.