CVE-2026-106122
Received
Received - Intake
RabbitMQ Java Client UTF-8 Decoding Shortstr Overflow
Vulnerability report for CVE-2026-106122, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: GitHub, Inc.
Description
Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| rabbitmq | rabbitmq-java-client | < 5.36.0 |
| com.rabbitmq | amqp-client | < 5.36.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-172 | The product does not properly encode or decode the data, resulting in unexpected values. |
| CWE-248 | An exception is thrown from a function, but it is not caught. |