CVE-2026-106121Medium· 4.9▾ TwilightPoC availableThe RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 27 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106122Medium· 6.0The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
CVE-2026-106123Medium· 5.7The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
CVE-2026-75516High· 8.7The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
CVE-2026-66078Low· 2.1RabbitMQ is a messaging and streaming broker
CVE-2026-67241Medium· 4.8RabbitMQ is a messaging and streaming broker
CVE-2026-67242Medium· 6.3RabbitMQ is a messaging and streaming broker