Vulnerability in RabbitMQ Java Client Affects Java Applications
CVE-2026-63337
7.5HIGH
What is CVE-2026-63337?
The RabbitMQ Java client library, used for connecting Java applications to RabbitMQ nodes, has a vulnerability that allows remote attackers to exploit class initialization issues. In versions before 5.33.0, the library improperly handles the javaReturnType value received from untrusted system responses, allowing for the triggering of static initializers of pre-existing classes in the victim's JVM. This exploitation could lead to significant security concerns, including breaches of confidentiality, integrity, and availability within the affected client process. The issue was addressed in version 5.33.0.
Affected Version(s)
rabbitmq-java-client < 5.33.0
