VYPR

Rabbitmq Java Client

by Rabbitmq

Source repositories

CVEs (9)

  • CVE-2020-36282CriMar 12, 2021
    risk 0.57cvss 9.8epss 0.03

    JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.

  • CVE-2026-75516HigSep 16, 2026
    risk 0.50cvss —epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines…

  • CVE-2026-69220HigAug 18, 2026
    risk 0.50cvss —epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call…

  • CVE-2026-69219HigAug 18, 2026
    risk 0.50cvss —epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below…

  • CVE-2026-63337HigAug 18, 2026
    risk 0.42cvss —epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through…

  • CVE-2026-63335MedAug 18, 2026
    risk 0.34cvss —epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header…

  • CVE-2026-63336MedAug 18, 2026
    risk 0.26cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure…

  • CVE-2023-46120MedOct 25, 2023
    risk 0.25cvss 4.9epss 0.01

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error.…

  • CVE-2026-61634NonAug 18, 2026
    risk 0.00cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java…