Bug 2525069 (CVE-2026-59272)

Summary: CVE-2026-59272 org.apache.logging.log4j/log4j-core: org.springframework.amqp/spring-amqp: Log4j2 AMQP Appender: Information disclosure due to disabled TLS hostname verification
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: alinfoot, amctagga, anujha, aoconnor, asoldano, asyoung, ataylor, bbaranow, bbrownin, bmaxwell, bniver, bstansbe, csutherl, dbruscin, dlofthou, dsoumis, dtrifiro, ehugonne, ewittman, flucifre, fmariani, fmongiar, gmalinko, gmeno, groman, istudens, ivassile, iweiss, janstey, jclere, jhollowa, jnethert, jwon, kaycoth, kvanderr, mbenjamin, mcarlett, mhackett, mosmerov, msvehla, nipatil, nwallace, pantinor, pberan, pdelbell, pesilva, pjindal, plodge, pmackay, prichard, rbryant, rhel-process-autobot, rkubis, rmaucher, rstancel, rstepani, sostapov, sthirugn, szappis, tcunning, thjenkin, vdosoudi, vereddy, watson-tool-maintainers, weaton, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the Log4j2 AMQP Appender. When configured to ship logs to RabbitMQ over Transport Layer Security (TLS), the appender disables hostname verification by default. This misconfiguration allows a remote attacker to perform a man-in-the-middle (MITM) attack, intercepting sensitive log events. This can lead to unauthorized information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2528018, 2528021, 2528022, 2528019, 2528020    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-27 16:57:04 UTC
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier