RabbitMQ Java Client & Go Library Patched for Four Vulnerabilities, Including DoS Flaw
RabbitMQ client libraries patched for four vulnerabilities, including a high-severity Java client flaw enabling DoS and credential exposure risks.

Key findings
- Four RabbitMQ vulnerabilities disclosed between Oct 6-8, 2026, affecting Java client and amqp091-go.
- High-severity CVE-2026-106122 in Java client allows DoS via malformed UTF-8 decoding.
- Medium-severity CVE-2026-106123 exposes credentials in Java client exceptions.
- Medium-severity CVE-2026-107386 bypasses frame-size mitigation in amqp091-go.
- Patches available in RabbitMQ Java client v5.35.0, v5.36.0, v5.37.0 and amqp091-go.
On October 6-8, 2026, a batch of four vulnerabilities was disclosed across RabbitMQ's Java client library and its amqp091-go implementation. The most severe, CVE-2026-106122, is a high-severity flaw in the Java client that could allow an attacker to cause a denial-of-service condition. The other vulnerabilities, all rated medium severity, include a bypass of frame-size mitigation in amqp091-go (CVE-2026-107386), plaintext credential exposure in exception messages in the Java client (CVE-2026-106123), and a JSON parsing vulnerability in the Java client (CVE-2026-106121).
The Java client library vulnerabilities, disclosed on October 6, 2026, affect versions prior to 5.36.0 (CVE-2026-106122), 5.35.0 (CVE-2026-106123), and 5.37.0 (CVE-2026-106121). CVE-2026-106122, a critical issue, arises from improper handling of malformed UTF-8 bytes during decoding, which can lead to an integer overflow when re-encoding, potentially causing a denial-of-service. CVE-2026-106123 involves the ConnectionFactoryConfigurator.load() method, which exposes sensitive credentials in exception messages if AMQP URI parsing fails. CVE-2026-106121 stems from a flaw in com.rabbitmq.tools.json.JSONReader.read(), where the scanner does not properly terminate on certain malformed JSON inputs, leading to potential parsing failures.
Separately, on October 8, 2026, CVE-2026-107386 was disclosed in the amqp091-go client library, affecting versions between 1.13.0 and 1.14.0. This vulnerability bypasses a previously implemented frame-size mitigation before the connection.tune handshake is completed. The issue arises because Connection.maxFrameSize incorrectly uses zero for both unnegotiated and unlimited states, allowing a malicious peer to exploit this before the connection is fully established.
The RabbitMQ team has addressed these vulnerabilities through updates to their client libraries. The Java client library has seen patches released with versions 5.36.0, 5.35.0, and 5.37.0 addressing CVE-2026-106122, CVE-2026-106123, and CVE-2026-106121 respectively. The amqp091-go client library has also been updated to fix CVE-2026-107386. Users are advised to update to the patched versions to mitigate these risks.
This batch of disclosures highlights the importance of keeping client libraries updated, as vulnerabilities in these components can have significant security implications, ranging from data exposure to denial-of-service conditions. Users of RabbitMQ should ensure they are running the latest versions of the relevant client libraries to protect their messaging infrastructure.