Encoding Error in RabbitMQ Java Client Library - #VU151668

 

Encoding Error in RabbitMQ Java Client Library - #VU151668

Published: September 22, 2026


Vulnerability identifier: #VU151668
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-172
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to an encoding error in ValueReader.readShortstr and ValueWriter.writeShortstr when processing an AMQP message with malformed UTF-8 shortstr properties. A remote user can send a specially crafted AMQP message to cause a denial of service.

The issue affects RPC consumers that echo received shortstr property values, and the unacknowledged message is requeued for subsequent consumers.


Affected software

RabbitMQ Java Client Library

Remediation

Install security update from vendor's website.

RabbitMQ Java Client Library - update to 5.36.0

External References

Related Security Bulletins