Vulnerability in RabbitMQ Java Client Affects Java Applications
CVE-2026-63337

7.5HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
18 August 2026

What is CVE-2026-63337?

The RabbitMQ Java client library, used for connecting Java applications to RabbitMQ nodes, has a vulnerability that allows remote attackers to exploit class initialization issues. In versions before 5.33.0, the library improperly handles the javaReturnType value received from untrusted system responses, allowing for the triggering of static initializers of pre-existing classes in the victim's JVM. This exploitation could lead to significant security concerns, including breaches of confidentiality, integrity, and availability within the affected client process. The issue was addressed in version 5.33.0.

Affected Version(s)

rabbitmq-java-client < 5.33.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.