CVE-2026-106122
CVE-2026-106122 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.0. The underlying weakness is classified as CWE-172.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.0)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-172
- Published:
- Last modified:
Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.
Frequently asked questions
- What is CVE-2026-106122?
- The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode beyond the AMQP shortstr limit enforced by ValueWriter.writeShortstr. An attacker who can submit an RPC message with a malformed echoed property can cause reply publication in RpcServer.mainloop() or tutorial-style consumers to throw an unchecked exception before acknowledgement. The broker requeues the message, allowing the same message to disable replacement consumers until the queue is purged. This issue is fixed in version 5.36.0.
- How severe is CVE-2026-106122?
- CVE-2026-106122 has a CVSS 4.0 base score of 6.0, rated medium severity.
- Is CVE-2026-106122 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-106122?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-106122 published?
- CVE-2026-106122 was published on 2026-10-06.
References
- https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2065
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx
Other CWE-172 vulnerabilities
- CVE-2019-10160 — Critical (CVSS 9.8): A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3…
- CVE-2018-3777 — Critical (CVSS 9.8): Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API…
- CVE-2016-6691 — Critical (CVSS 9.8): service/jni/com_android_server_wifi_Gbk2Utf.cpp in the Qualcomm Wi-Fi gbk2utf module in Android before 2016-10-05…
- CVE-2025-27110 — High (CVSS 7.5): Libmodsecurity is one component of the ModSecurity v3 project. The library codebase serves as an interface to…
- CVE-2026-100891 — High (CVSS 7.3): A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function…
- CVE-2026-48784 — Medium (CVSS 6.1): Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53,…