Threat Advisory

RabbitMQ Client Flaw Triggers Denial of Service in RPC Applications

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-106122 describes a denial-of-service vulnerability in the RabbitMQ Java client where a malicious AMQP message containing malformed UTF-8 data in a shortstr property can cause an RPC consumer to fail and remain disabled because the message is repeatedly requeued. The issue affects versions up to 5.35.0 and is fixed in 5.36.0. The vulnerability has a CVSS v4.0 score of 6.0 (Medium).

RECOMMENDATION:

We strongly recommend you to update RabbitMQ to version 5.36.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-106122 describes a denial-of-service vulnerability in the RabbitMQ Java client where a malicious AMQP message containing malformed UTF-8 data in a shortstr property can cause an RPC consumer to fail and remain disabled because the message is repeatedly requeued. The issue affects versions up to 5.35.0 and is fixed in 5.36.0. The vulnerability has a CVSS v4.0 score of 6.0 (Medium).

RECOMMENDATION:

We strongly recommend you to update RabbitMQ to version 5.36.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu