Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-63337: RabbitMQ Java client can let attackers run code
CVE-2026-63337 · published 4 days ago
Summary
The RabbitMQ Java client library (com.rabbitmq:amqp-client) had a flaw that could allow an attacker to execute code on your system. Updated versions have been released that remove this risk. Make sure you upgrade to the latest patched version of the RabbitMQ Java client as soon as possible.
What to do
- Update rabbitmq com.rabbitmq:amqp-client to version 5.33.0.
- Update com.rabbitmq:amqp-client to version 5.25.0-aikido.1.
- Update io.root.com.rabbitmq:amqp-client to version 5.25.0-root.io.1.
- Update com.rabbitmq:amqp-client to version 5.25.0-aikido.2.
- Update io.root.com.rabbitmq:amqp-client to version 5.25.0-root.io.2.
- Update com.rabbitmq:amqp-client to version 5.27.1-aikido.1.
- Update io.root.com.rabbitmq:amqp-client to version 5.27.1-root.io.1.
- Update com.rabbitmq:amqp-client to version 5.27.1-aikido.2.
- Update io.root.com.rabbitmq:amqp-client to version 5.27.1-root.io.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:18.04:LTS | canonical | rabbitmq-java-client | All versions |
| Ubuntu:20.04:LTS | canonical | rabbitmq-java-client | All versions |
| Ubuntu:22.04:LTS | canonical | rabbitmq-java-client | All versions |
| Ubuntu:24.04:LTS | canonical | rabbitmq-java-client | All versions |
| Ubuntu:26.04:LTS | canonical | rabbitmq-java-client | All versions |
| – | rabbitmq | rabbitmq-java-client | < 5.33.0 |
| maven | rabbitmq | com.rabbitmq:amqp-client |
< 5.33.0 Fix: upgrade to 5.33.0
|
| Debian:11 | debian | rabbitmq-java-client | All versions |
| Debian:12 | debian | rabbitmq-java-client | All versions |
| Debian:13 | debian | rabbitmq-java-client | All versions |
| Debian:14 | debian | rabbitmq-java-client | All versions |
| Root:Maven | – | com.rabbitmq:amqp-client |
< 5.25.0-aikido.1 < 5.25.0-aikido.2 < 5.27.1-aikido.1 < 5.27.1-aikido.2 Fix: upgrade to 5.25.0-aikido.1
|
| Root:Maven | – | io.root.com.rabbitmq:amqp-client |
< 5.25.0-root.io.1 < 5.25.0-root.io.2 < 5.27.1-root.io.1 < 5.27.1-root.io.2 Fix: upgrade to 5.25.0-root.io.1
|
Original advisory text
CVE-2026-63337 in com.rabbitmq:amqp-client - Patched by Root
Root has patched CVE-2026-63337 in the com.rabbitmq:amqp-client package for Root:Maven. Multiple fixed versions available.
References
- https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b8... Patch
- https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e962... Patch
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2000 Patch
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2002 Patch
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0 URL
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-p... Vendor Advisory
- https://github.com/advisories/GHSA-6g32-pxv4-2wfj
- https://www.cve.org/CVERecord?id=CVE-2026-63337 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-63337 Third Party Advisory
- https://github.com/rabbitmq/rabbitmq-java-client Product
- https://security-tracker.debian.org/tracker/CVE-2026-63337 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63337... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-63337 Vendor Advisory
Severity
9.4
Critical
CVSS 4.0: 7.5 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen18 Aug 2026
Sources
UBUNTU-CVE-2026-63337 · OSV
CVE-2026-63337 · NVD
CVE-2026-63337 · MITRE
GHSA-6g32-pxv4-2wfj · GHSA
GHSA-6g32-pxv4-2wfj · OSV
DEBIAN-CVE-2026-63337 · OSV
CVE-2026-63337 · OSV
Track software like this
Free during beta