PatchSiren cyber security CVE debrief
CVE-2026-106122 RabbitMQ CVE debrief
A single AMQP message with malformed UTF-8 in a shortstr property can permanently disable a Java client RPC consumer in RabbitMQ. The client decodes malformed bytes into U+FFFD replacement characters, which re-encodes to 3 bytes, exceeding the 255-byte shortstr limit. When the application echoes that value back, as the documented RPC pattern does, the encoder throws an unchecked `IllegalArgumentException`, killing the consumer loop or tearing down the channel. The message is never acknowledged, so the broker requeues it and it disables the next consumer that picks it up. Recovery does not help; the service stays down until an operator manually purges the queue.
- Vendor
- RabbitMQ
- Product
- RabbitMQ Java client (com.rabbitmq:amqp-client)
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for RabbitMQ deployments, specifically those using the Java client, should assess exposure and prioritize updating to version 5.36.0 or later of com.rabbitmq:amqp-client.
Why it matters
Defenders should care about CVE-2026-106122 because it can cause permanent disablement of RPC consumers in RabbitMQ, leading to potential service disruption. The vulnerability can be triggered by a single malformed AMQP message, and recovery requires manual intervention. Updating to version 5.36.0 or later of com.rabbitmq:amqp-client can mitigate this issue.
- Permanent disablement of RPC consumers
- Potential for service disruption
- Need for manual queue purge for recovery
Technical summary
The vulnerability occurs in the RabbitMQ Java client, specifically in the `ValueReader.readShortstr` method, which decodes malformed UTF-8 bytes into U+FFFD replacement characters. These characters re-encode to 3 bytes, exceeding the 255-byte shortstr limit, causing an `IllegalArgumentException` when echoed back. This issue can be triggered by a single malformed AMQP message, and recovery requires manual intervention. Defenders should prioritize verifying and updating to version 5.36.0 or later of com.rabbitmq:amqp-client, assessing exposure in their RabbitMQ deployments, and monitoring for similar malformed UTF-8 issues. The client decodes malformed bytes into U+FFFD replacement characters. Each of those reenc
Defensive priority
Defenders should prioritize verifying and updating to version 5.36.0 or later of com.rabbitmq:amqp-client, assessing exposure in their RabbitMQ deployments, and monitoring for similar malformed UTF-8 issues.
Recommended defensive actions
- Verify and update to version 5.36.0 or later of com.rabbitmq:amqp-client
- Assess exposure in RabbitMQ deployments
- Monitor for similar malformed UTF-8 issues
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The source corpus provides detailed information about the vulnerability, including a summary, details, and references. However, it does not provide information on exploitation or specific victims. Defenders should verify and update to version 5.36.0 or later of com.rabbitmq:amqp-client, assess exposure in RabbitMQ deployments, and monitor for similar malformed UTF-8 issues. Evidence is limited to public sources and may not reflect all affected systems or exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Maven/GHSA-7822-rcf6-97fx.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-7822-rcf6-97fx
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/pull/2065
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/commit/b8bd750fa8c90690e859b18d6343b34421309020
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.36.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.