What is CVE-2026-63337?
This vulnerability exists in the RabbitMQ Java client library, where an untrusted JSON response is deserialized without proper validation, potentially leading to remote code execution. Applications using versions prior to 5.33.0 are affected and should upgrade immediately.
Azərbaycanca: Bu zəiflik RabbitMQ Java müştəri kitabxanasında aşkarlanıb və tətbiqlərin etibarsız mənbədən gələn JSON cavabını işləyərkən təhlükəli kod icrasına yol aça bilər. 5.33.0 versiyasından əvvəlki kitabxanaları istifadə edən Java və JVM əsaslı tətbiqlər təsirlənir, onlara dərhal yeniləmə tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ1
What can an attacker achieve by exploiting CVE-2026-63337?
This vulnerability can lead to remote code execution when processing a JSON response from an untrusted source.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.