Vulnerability in RabbitMQ Java Client Library Affects JVM-Based Applications
CVE-2026-106122
6MEDIUM
What is CVE-2026-106122?
The RabbitMQ Java client library allows Java and JVM-based applications to interact with RabbitMQ nodes. Prior to version 5.36.0, a vulnerability exists in the ValueReader.readShortstr function, which improperly decodes malformed UTF-8 bytes, potentially leading to messages that exceed the AMQP shortstr limit. An attacker could exploit this by sending a malformed RPC message, causing unchecked exceptions in RpcServer.mainloop() or in consumer applications before message acknowledgment. This results in messages being requeued, thereby disrupting the functionality of replacement consumers until the queue is cleared. The issue has been resolved in version 5.36.0.
Affected Version(s)
amqp-client < 5.36.0
rabbitmq-java-client < 5.36.0
