CVE-2026-106122
Received Received - Intake

RabbitMQ Java Client UTF-8 Decoding Shortstr Overflow

Vulnerability report for CVE-2026-106122, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rabbitmq rabbitmq-java-client < 5.36.0
com.rabbitmq amqp-client < 5.36.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-172 The product does not properly encode or decode the data, resulting in unexpected values.
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The RabbitMQ Java client library before version 5.36.0 has a flaw in how it handles malformed UTF-8 bytes. When decoding these bytes, it replaces them with special characters that can expand beyond the allowed size limit for short strings in RabbitMQ. This causes an error when processing RPC messages, leading to unchecked exceptions and message requeuing. The issue disrupts consumers until the queue is purged.

Detection Guidance

Detecting this vulnerability requires checking the version of the RabbitMQ Java client library in use. If your application uses RabbitMQ Java client versions prior to 5.36.0, it is vulnerable. Inspect dependency files like pom.xml (Maven) or build.gradle (Gradle) for the client version.

Impact Analysis

An attacker could exploit this to repeatedly crash your RabbitMQ consumers by sending specially crafted messages. This would cause downtime for message processing, potential data loss if messages are not properly handled, and require manual intervention to purge the affected queues.

Mitigation Strategies

Upgrade the RabbitMQ Java client library to version 5.36.0 or later immediately. This fixes the UTF-8 decoding issue that causes the vulnerability. After upgrading, monitor logs for unchecked exceptions in RpcServer.mainloop() or consumer threads to confirm the issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106122. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart