Impact
The vulnerability occurs when the RabbitMQ Java client library decodes malformed UTF‑8 bytes in short string properties into replacement characters that, when re‑encoded, exceed the AMQP short string size limit. The resulting unchecked exception in the RPC server causes consumers that handle the message to be permanently disabled. The broker re‑queues the offending message, so the same malformed message will continue to disable consumers until the queue is purged, effectively denying the affected consumers service.
Affected Systems
Affected products are the RabbitMQ Java client libraries from the vendors com.rabbitmq:amqp‑client and rabbitmq:rabbitmq‑java‑client. All versions before 5.36.0 are vulnerable; the issue was fixed in version 5.36.0. Upgrade to 5.36.0 or later on all client applications that interact with RabbitMQ.
Risk and Exploitability
The CVSS score of 6 classifies the vulnerability as moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be able to submit an RPC message with a malformed property, which can be performed from any client with connectivity to the broker. The attack vector is inferred to be remote, as it requires network access to the RabbitMQ server. Once the malformed message is processed, the same message will continually disable consumers until remedial action is taken.
OpenCVE Enrichment