Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
Published: 2026-10-06
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (DoS)
Action: Apply Patch
AI Analysis

Impact

The defect resides in the RabbitMQ Java client’s JSONReader component, which fails to cease parsing when a JSON string or line comment is truncated. Truncated input causes the parser to endlessly append replacement markers until the heap is exhausted, or to leave a thread spinning on CPU when a comment lacks a newline terminator, both of which produce a denial of service. The flaw aligns with CWE‑835 (Infinite Loop). The effect is a loss of availability for any service that relies on the client to process JSON‑RPC messages, without any direct compromise of confidentiality or integrity.

Affected Systems

Vendors marked as com.rabbitmq:amqp-client and rabbitmq:rabbitmq-java-client are affected. This vulnerability exists in every release prior to version 5.37.0 of the RabbitMQ Java Client library—any Java or JVM‑based application that depends on an older client will be exposed. The upgrade to 5.37.0 eliminates the issue.

Risk and Exploitability

This flaw carries a CVSS score of 4.9, which places it in the medium severity range. Exploitability is constrained to scenarios where an attacker can inject truncated or malformed JSON‑RPC messages into a client that is actively consuming requests, such as a malicious RabbitMQ node or compromised network device. Because EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, there is no publicly known active exploitation, yet the possibility of in‑network misuse remains. The lack of a remote code execution vector limits the attack surface, but a DoS can still disrupt critical messaging infrastructure.

Generated by OpenCVE AI on October 6, 2026 at 19:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RabbitMQ Java Client library to version 5.37.0 or later.
  • If an upgrade is not immediately possible, enforce input size limits on JSON‑RPC requests to bound the parsing effort and configure the JVM with a realistic maximum heap size to prevent uncontrolled memory growth.
  • Implement application‑level monitoring that flags sustained high CPU usage or memory exhaustion, and isolate the client process in a confined environment or container to reduce the impact scope.

Generated by OpenCVE AI on October 6, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
Title RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T18:32:46.845Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106121

cve-icon Vulnrichment

Updated: 2026-10-06T18:32:26.973Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:43.193

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')