SCA: security update for com.rabbitmq:amqp-client (GHSA-cqgh-8p3p-mx4m)

medium Tenable Cloud Security Plugin ID 473775

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with
RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input
ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at
CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for
JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers
until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU
indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0. (CVE-2026-106121)

Solution

Update the com.rabbitmq:amqp-client library and its related packages to version 5.36.1 or later.

See Also

https://github.com/advisories/GHSA-cqgh-8p3p-mx4m

Plugin Details

Severity: Medium

ID: 473775

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/8/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.67

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:N/A:C

CVSS Score Source: CVE-2026-106121

CVSS v3

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106121

cwe: CWE-835