CVE-2020-36282: Rabbitmq Jms Client

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.

Affected products

  • Rabbitmq Jms Client: from 1.0.0, before 1.15.2 (fixed in 1.15.2); from 2.0.0, before 2.2.0 (fixed in 2.2.0)

Published 2021-03-12. Last modified 2026-06-17.