com.rabbitmq:amqp-client
Maven12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.rabbitmq:amqp-clientpage 1 of 1
- CVE-2018-11087MEDIUMCVSS 5.9EG 5.9fixed in 4.8.0 or 5.4.0, by version range2018-09-14
vulnerable: 5.0.0 ... 5.3.0 (6 versions)
Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to vie…
- CVE-2023-46120HIGHCVSS 7.5EG 7.5fixed in 5.18.02023-10-25
vulnerable: 1.3.0 ... 5.9.0 (134 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memor…
- CVE-2026-106121HIGHCVSS 7.5EG 7.5fixed in 5.36.12026-10-06
vulnerable: 1.3.0 ... 5.9.0 (155 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or…
- CVE-2026-106122HIGHCVSS 7.5EG 7.5fixed in 5.36.02026-10-06
vulnerable: 1.3.0 ... 5.9.0 (154 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.36.0, ValueReader.readShortstr decodes malformed UTF-8 bytes into replacement characters that can re-encode …
- CVE-2026-106123MEDIUMCVSS 5.5EG 5.5fixed in 5.35.02026-10-06
vulnerable: 1.3.0 ... 5.9.0 (153 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI pa…
- CVE-2026-61634UnratedEG not assessedfixed in 5.33.02026-08-18
vulnerable: 1.3.0 ... 5.9.0 (150 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rab…
- CVE-2026-63335MEDIUMCVSS 6.3EG 6.3fixed in 5.31.02026-08-18
vulnerable: 1.3.0 ... 5.9.0 (148 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processe…
- CVE-2026-63336MEDIUMCVSS 5.1EG 5.1fixed in 5.33.02026-08-18
vulnerable: 1.3.0 ... 5.9.0 (150 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) co…
- CVE-2026-63337HIGHCVSS 7.5EG 7.5fixed in 5.33.02026-08-18
vulnerable: 1.3.0 ... 5.9.0 (150 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system…
- CVE-2026-69219HIGHCVSS 8.7EG 8.7fixed in 5.33.12026-08-18
vulnerable: 1.3.0 ... 5.9.0 (151 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-de…
- CVE-2026-69220HIGHCVSS 8.7EG 8.7fixed in 5.33.12026-08-18
vulnerable: 1.3.0 ... 5.9.0 (151 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.…
- CVE-2026-75516HIGHCVSS 8.7EG 8.7fixed in 5.34.02026-09-16
vulnerable: 1.3.0 ... 5.9.0 (152 versions)
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune nego…
Check whether com.rabbitmq:amqp-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.rabbitmq:amqp-client CVEs against the assets you own.
Book a Demo →