Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.
Published: 2026-08-18
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A malicious AMQP server or network intermediary can send an AMQP frame containing an extraordinarily deep nesting of tables or arrays. The client library’s ValueReader parses these value types recursively without enforcing a depth limit, which can cause the Java virtual machine to exhaust stack space and trigger a StackOverflowError. The error aborts the client’s input thread, effectively terminating the application without a graceful shutdown and thereby denying service to legitimate clients.

Affected Systems

The vulnerability exists in the RabbitMQ Java client library for any version prior to 5.33.1. Applications that rely on older releases of this library and that connect to RabbitMQ nodes are potentially impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high risk of exploitation, and although an EPSS value is not provided, the absence of a depth check means the flaw can be leveraged remotely by an attacker who can control the server or relay traffic. The issue is not listed in CISA’s KEV catalog, but the severity and straightforward exploitation scenario warrant immediate attention.

Generated by OpenCVE AI on August 18, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the RabbitMQ Java client library to version 5.33.1 or later, which enforces a nesting depth limit during ValueReader parsing
  • Ensure that the client application receives input only from trusted, authenticated RabbitMQ nodes to prevent receipt of malformed frames
  • Consider implementing network-level packet filtering to block frames that exceed the AMQP frame size or contain abnormal nesting patterns

Generated by OpenCVE AI on August 18, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-93j5-89vc-pph4 RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
History

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.
Title RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-18T17:45:59.023Z

Reserved: 2026-08-03T16:57:50.125Z

Link: CVE-2026-69220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T17:17:01.497

Modified: 2026-08-18T17:17:01.497

Link: CVE-2026-69220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T17:30:15Z

Weaknesses