PT-2026-80233 · Maven · Com.Rabbitmq:Amqp-Client
Published
2026-08-18
·
Updated
2026-08-18
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Summary
ValueReader.readBytes() allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.Vulnerable Code
src/main/java/com/rabbitmq/client/impl/ValueReader.java lines 83-95:java
private static byte[] readBytes(final DataInputStream in) throws IOException {
final long contentLength = unsignedExtend(in.readInt());
if(contentLength < Integer.MAX VALUE) {
final byte[] buffer = new byte[(int)contentLength]; // allocates before reading
in.readFully(buffer);
return buffer;
}
}Attack Scenario
A malicious AMQP server sends a LongString field (type tag 'S') with declared length
0x7FFFFFFE (2,147,483,646). The check contentLength < Integer.MAX VALUE passes. new byte[2147483646] attempts ~2GB allocation, causing OutOfMemoryError before readFully() attempts to read data.The allocation size is attacker-controlled and is NOT validated against the frame size or
TruncatedInputStream bounds. Exploitable pre-authentication via connection.start server-properties table.Impact
Denial of service via JVM
OutOfMemoryError. Crashes the entire JVM.CWE
CWE-789: Memory Allocation with Excessive Size Value
Remediation
Validate
contentLength against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Com.Rabbitmq:Amqp-Client