CVE-2026-63336Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname verification disabled, causing arbitrary server certificates, including self-signed certificates, to be accepted. A network attacker able to intercept a TLS connection can impersonate the RabbitMQ broker, read protected AMQP traffic, and modify traffic without certificate or hostname validation. The fix changes the production TLS helpers to use the JVM default trust store and enables hostname verification, while retaining an explicitly named development-only no-verification helper. This issue is fixed in version 5.33.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 208-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-63336 The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.Connectio… https://www.cve.org/CVERecord?id=CVE-2026-63336 ----- Traducción: CVE-2026-63336 La … https://infoflow.cloud`

    Post summary

    The text merely references CVE‑2026‑63336 and provides a brief description of the affected RabbitMQ Java client library, without further technical details, exploit information, or mitigation guidance.

    0000026
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-63336 The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.Connectio… https://www.cve.org/CVERecord?id=CVE-2026-63336

    Post summary

    The text is a brief notice of CVE‑2026‑63336, noting a flaw in the RabbitMQ Java client library prior to version 5.33.0, but it does not contain any PoC, exploit, patch, or detailed technical information.

    000001.0K
    58.0K followersView on X

Explore more