Vulnerability in RabbitMQ Java Client Library Affects JVM-Based Applications
CVE-2026-106122

6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106122?

The RabbitMQ Java client library allows Java and JVM-based applications to interact with RabbitMQ nodes. Prior to version 5.36.0, a vulnerability exists in the ValueReader.readShortstr function, which improperly decodes malformed UTF-8 bytes, potentially leading to messages that exceed the AMQP shortstr limit. An attacker could exploit this by sending a malformed RPC message, causing unchecked exceptions in RpcServer.mainloop() or in consumer applications before message acknowledgment. This results in messages being requeued, thereby disrupting the functionality of replacement consumers until the queue is cleared. The issue has been resolved in version 5.36.0.

Affected Version(s)

amqp-client < 5.36.0

rabbitmq-java-client < 5.36.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.