Impact
The vulnerability resides in the RabbitMQ Java client library, which misinterprets a zero frameMax value as unlimited when computing the maximum inbound message body size. This results in the client allocating an unbounded byte array during frame parsing, exposing the application to memory exhaustion and potential denial of service. The bug is categorized as a Resource Exhaustion flaw (CWE‑770).
Affected Systems
All RabbitMQ Java client versions released before 5.34.0 are affected. The vulnerability is exploitable in any Java or JVM‑based application that uses the library to connect to a RabbitMQ broker and relies on the default frameMax configuration of zero, which is interpreted as unlimited by the client.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% reflects a low likelihood of current exploitation. The exploit could be triggered by a malicious AMQP server or a man‑in‑the‑middle attacker that alters the Connection.Tune negotiation, causing the client to accept oversized frames that deplete heap space. Because the bug requires the attacker to send frames during the connection establishment phase, the exploit is most relevant in environments where the client connects to untrusted or network‑proxied brokers.
OpenCVE Enrichment
Github GHSA