CVE-2026-106122 describes a denial-of-service vulnerability in the RabbitMQ Java client where a malicious AMQP message containing malformed UTF-8 data in a shortstr property can cause an RPC consumer to fail and remain disabled because the message is repeatedly requeued. The issue affects versions up to 5.35.0 and is fixed in 5.36.0. The vulnerability has a CVSS v4.0 score of 6.0 (Medium).
We strongly recommend you to update RabbitMQ to version 5.36.0.[/subscribe_to_unlock_form]
CVE-2026-106122 describes a denial-of-service vulnerability in the RabbitMQ Java client where a malicious AMQP message containing malformed UTF-8 data in a shortstr property can cause an RPC consumer to fail and remain disabled because the message is repeatedly requeued. The issue affects versions up to 5.35.0 and is fixed in 5.36.0. The vulnerability has a CVSS v4.0 score of 6.0 (Medium).
We strongly recommend you to update RabbitMQ to version 5.36.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]