Impact
The defect resides in the RabbitMQ Java client’s JSONReader component, which fails to cease parsing when a JSON string or line comment is truncated. Truncated input causes the parser to endlessly append replacement markers until the heap is exhausted, or to leave a thread spinning on CPU when a comment lacks a newline terminator, both of which produce a denial of service. The flaw aligns with CWE‑835 (Infinite Loop). The effect is a loss of availability for any service that relies on the client to process JSON‑RPC messages, without any direct compromise of confidentiality or integrity.
Affected Systems
Vendors marked as com.rabbitmq:amqp-client and rabbitmq:rabbitmq-java-client are affected. This vulnerability exists in every release prior to version 5.37.0 of the RabbitMQ Java Client library—any Java or JVM‑based application that depends on an older client will be exposed. The upgrade to 5.37.0 eliminates the issue.
Risk and Exploitability
This flaw carries a CVSS score of 4.9, which places it in the medium severity range. Exploitability is constrained to scenarios where an attacker can inject truncated or malformed JSON‑RPC messages into a client that is actively consuming requests, such as a malicious RabbitMQ node or compromised network device. Because EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, there is no publicly known active exploitation, yet the possibility of in‑network misuse remains. The lack of a remote code execution vector limits the attack surface, but a DoS can still disrupt critical messaging infrastructure.
OpenCVE Enrichment