---
id: CVE-2026-106122
title: >-
  The RabbitMQ Java client library allows Java and JVM-based applications to
  connect to and interact with RabbitMQ nodes
summary: >-
  The RabbitMQ Java client library allows Java and JVM-based applications to
  connect to and interact with RabbitMQ nodes. Prior to 5.36.0,
  ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement
  characters that can re-encod…
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-172
  - CWE-248
vendor: rabbitmq
product: rabbitmq-java-client
affected:
  - rabbitmq-java-client < 5.36.0
  - amqp-client < 5.36.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:03:40.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106122'
references:
  - url: >-
      https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-java-client/pull/2065'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-06T18:23:11.530141Z'
cvssSource: cna
ingestedAt: '2026-10-06T19:13:33.939Z'
---

## Overview

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
