Report: CVE-2026-40971 - Spring Boot RabbitMQ SSL Hostname Verification Bypass - Analysis

Report: CVE-2026-40971 - Spring Boot RabbitMQ SSL Hostname Verification Bypass - Analysis

CVE ID :CVE-2026-40971 Published : April 27, 2026, 11:16 p.m. | 43 minutes ago Description :When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 27, 2026