Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.
Published: 2026-10-06
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability occurs when the RabbitMQ Java client library decodes malformed UTF‑8 bytes in short string properties into replacement characters that, when re‑encoded, exceed the AMQP short string size limit. The resulting unchecked exception in the RPC server causes consumers that handle the message to be permanently disabled. The broker re‑queues the offending message, so the same malformed message will continue to disable consumers until the queue is purged, effectively denying the affected consumers service.

Affected Systems

Affected products are the RabbitMQ Java client libraries from the vendors com.rabbitmq:amqp‑client and rabbitmq:rabbitmq‑java‑client. All versions before 5.36.0 are vulnerable; the issue was fixed in version 5.36.0. Upgrade to 5.36.0 or later on all client applications that interact with RabbitMQ.

Risk and Exploitability

The CVSS score of 6 classifies the vulnerability as moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to submit an RPC message with a malformed property, which can be performed from any client with connectivity to the broker. The attack vector is inferred to be remote, as it requires network access to the RabbitMQ server. Once the malformed message is processed, the same message will continually disable consumers until remedial action is taken.

Generated by OpenCVE AI on October 6, 2026 at 19:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RabbitMQ Java client library to version 5.36.0 or later on all systems that use it.
  • Ensure that any updated consumer code is redeployed and that no legacy clients remain connected with the vulnerable library.
  • If consumers are already disabled, purge the affected queues or restart the consumer processes to re‑enable them, and monitor for additional malformed messages.

Generated by OpenCVE AI on October 6, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.
Title RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers
Weaknesses CWE-172
CWE-248
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T18:23:24.929Z

Reserved: 2026-10-06T15:33:55.334Z

Link: CVE-2026-106122

cve-icon Vulnrichment

Updated: 2026-10-06T18:23:19.475Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:43.467

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses