Improper Certificate Validation Affecting com.rabbitmq:amqp-client package, versions [,5.33.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMRABBITMQ-18958662
  • published19 Aug 2026
  • disclosed18 Aug 2026
  • creditUnknown

Introduced: 18 Aug 2026

NewCVE-2026-63336  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade com.rabbitmq:amqp-client to version 5.33.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation via the ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) paths in ConnectionFactory.java. An attacker can intercept and tamper with AMQP traffic by presenting any certificate during a TLS connection setup. Because the default SSL setup trusts every server certificate and does not verify the broker hostname, a man-in-the-middle can impersonate the RabbitMQ server and expose or alter client communications, including credentials and application messages.

CVSS Base Scores

version 4.0
version 3.1