PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106122 RabbitMQ CVE debrief

A single AMQP message with malformed UTF-8 in a shortstr property can permanently disable a Java client RPC consumer in RabbitMQ. The client decodes malformed bytes into U+FFFD replacement characters, which re-encodes to 3 bytes, exceeding the 255-byte shortstr limit. When the application echoes that value back, as the documented RPC pattern does, the encoder throws an unchecked `IllegalArgumentException`, killing the consumer loop or tearing down the channel. The message is never acknowledged, so the broker requeues it and it disables the next consumer that picks it up. Recovery does not help; the service stays down until an operator manually purges the queue.

Vendor
RabbitMQ
Product
RabbitMQ Java client (com.rabbitmq:amqp-client)
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for RabbitMQ deployments, specifically those using the Java client, should assess exposure and prioritize updating to version 5.36.0 or later of com.rabbitmq:amqp-client.

Why it matters

Defenders should care about CVE-2026-106122 because it can cause permanent disablement of RPC consumers in RabbitMQ, leading to potential service disruption. The vulnerability can be triggered by a single malformed AMQP message, and recovery requires manual intervention. Updating to version 5.36.0 or later of com.rabbitmq:amqp-client can mitigate this issue.

  • Permanent disablement of RPC consumers
  • Potential for service disruption
  • Need for manual queue purge for recovery

Technical summary

The vulnerability occurs in the RabbitMQ Java client, specifically in the `ValueReader.readShortstr` method, which decodes malformed UTF-8 bytes into U+FFFD replacement characters. These characters re-encode to 3 bytes, exceeding the 255-byte shortstr limit, causing an `IllegalArgumentException` when echoed back. This issue can be triggered by a single malformed AMQP message, and recovery requires manual intervention. Defenders should prioritize verifying and updating to version 5.36.0 or later of com.rabbitmq:amqp-client, assessing exposure in their RabbitMQ deployments, and monitoring for similar malformed UTF-8 issues. The client decodes malformed bytes into U+FFFD replacement characters. Each of those reenc

Defensive priority

Defenders should prioritize verifying and updating to version 5.36.0 or later of com.rabbitmq:amqp-client, assessing exposure in their RabbitMQ deployments, and monitoring for similar malformed UTF-8 issues.

Recommended defensive actions

  • Verify and update to version 5.36.0 or later of com.rabbitmq:amqp-client
  • Assess exposure in RabbitMQ deployments
  • Monitor for similar malformed UTF-8 issues
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The source corpus provides detailed information about the vulnerability, including a summary, details, and references. However, it does not provide information on exploitation or specific victims. Defenders should verify and update to version 5.36.0 or later of com.rabbitmq:amqp-client, assess exposure in RabbitMQ deployments, and monitor for similar malformed UTF-8 issues. Evidence is limited to public sources and may not reflect all affected systems or exploitation attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106122 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106122

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106122 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106122

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Maven/GHSA-7822-rcf6-97fx.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/pull/2065

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.