PT-2026-93899 · Vmware · Rabbitmq Java Client
CVE-2026-75516
·
Published
2026-07-08
·
Updated
2026-09-25
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rabbitmq-java-client versions prior to 5.34.0
Description
An issue exists in the
AMQConnection.start() function where the maxInboundMessageBodySize cap is bypassed during Connection.Tune negotiation. Because the AMQP specification defines a frameMax value of zero as unlimited, the use of Math.min(maxInboundMessageBodySize, frameMax) results in zero when both values are zero. This value is then processed by Utils.framePayloadLimit(int), which interprets zero as Integer.MAX VALUE, effectively disabling the memory protection cap. A malicious AMQP server or a man-in-the-middle attacker can exploit this by sending an oversized frame, causing Frame.readFrom() to allocate a massive byte array. This can lead to memory exhaustion and a denial of service (DoS) by terminating the client process through an Out-of-Memory (OOM) crash.Recommendations
Update rabbitmq-java-client to version 5.34.0.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq Java Client