OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-106121

MEDIUM · CVSS 4.9 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The RabbitMQ Java client library prior to version 5.37.0 is vulnerable due to a flaw in the JSON parsing mechanism, which can lead to denial of service (DoS) by exhausting heap memory or causing high CPU consumption. Applications using this library for JSON-RPC message handling should prioritize upgrading to version 5.37.0 to mitigate the risk of service interruptions. Organizations relying on Java and JVM-based applications that interact with RabbitMQ should assess their deployments for this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-106121
Severity
MEDIUM
CVSS
4.9
EPSS
0.50%
Java

Original NVD Description

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)