Denial of Service Vulnerability in RabbitMQ Java Client Library
CVE-2026-106121

4.9MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106121?

The RabbitMQ Java client library, essential for establishing connections between Java applications and RabbitMQ nodes, contains a vulnerability in its JSON parsing functionality. Prior to version 5.37.0, the method com.rabbitmq.tools.json.JSONReader.read() fails to terminate under certain conditions, particularly when it encounters an incomplete string or line comment. This flaw can lead to a denial of service, as the parser attempts to process continually without terminating, potentially exhausting the heap memory. System administrators using this version should upgrade to 5.37.0 to mitigate the risk.

Affected Version(s)

amqp-client < 5.36.1

rabbitmq-java-client < 5.36.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.