Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and ConnectionFactory.DEFAULT_FRAME_MAX is zero. When the client default and server-negotiated value are both zero, the result is passed to Utils.framePayloadLimit(int), which interprets zero as Integer.MAX_VALUE and disables the configured maxInboundMessageBodySize cap. A malicious AMQP server, or a man-in-the-middle attacker able to modify Connection.Tune and inject frames into the connection, can then send an oversized frame of any frame type, causing Frame.readFrom() to allocate a large byte array before content-level validation and potentially terminate the client process through memory exhaustion. This issue is fixed in version 5.34.0.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the RabbitMQ Java client library, which misinterprets a zero frameMax value as unlimited when computing the maximum inbound message body size. This results in the client allocating an unbounded byte array during frame parsing, exposing the application to memory exhaustion and potential denial of service. The bug is categorized as a Resource Exhaustion flaw (CWE‑770).

Affected Systems

All RabbitMQ Java client versions released before 5.34.0 are affected. The vulnerability is exploitable in any Java or JVM‑based application that uses the library to connect to a RabbitMQ broker and relies on the default frameMax configuration of zero, which is interpreted as unlimited by the client.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% reflects a low likelihood of current exploitation. The exploit could be triggered by a malicious AMQP server or a man‑in‑the‑middle attacker that alters the Connection.Tune negotiation, causing the client to accept oversized frames that deplete heap space. Because the bug requires the attacker to send frames during the connection establishment phase, the exploit is most relevant in environments where the client connects to untrusted or network‑proxied brokers.

Generated by OpenCVE AI on September 17, 2026 at 22:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RabbitMQ Java client library to version 5.34.0 or later.
  • Ensure that the ConnectionFactory.DEFAULT_FRAME_MAX is set to a safe non‑zero value and that the RabbitMQ broker’s frameMax is configured accordingly.
  • If an upgrade cannot be performed immediately, modify the application to enforce an explicit maximum frame size before invoking the client’s frame reading routine or monitor memory usage for early OOM detection.

Generated by OpenCVE AI on September 17, 2026 at 22:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jh4v-gfqj-7rhx RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq java-client
Vendors & Products Rabbitmq
Rabbitmq java-client

Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune negotiation even though AMQP defines frameMax value zero as unlimited and ConnectionFactory.DEFAULT_FRAME_MAX is zero. When the client default and server-negotiated value are both zero, the result is passed to Utils.framePayloadLimit(int), which interprets zero as Integer.MAX_VALUE and disables the configured maxInboundMessageBodySize cap. A malicious AMQP server, or a man-in-the-middle attacker able to modify Connection.Tune and inject frames into the connection, can then send an oversized frame of any frame type, causing Frame.readFrom() to allocate a large byte array before content-level validation and potentially terminate the client process through memory exhaustion. This issue is fixed in version 5.34.0.
Title RabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rabbitmq Java-client
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:17:25.002Z

Reserved: 2026-08-17T20:49:21.599Z

Link: CVE-2026-75516

cve-icon Vulnrichment

Updated: 2026-09-18T18:17:20.689Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:33.560

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-75516

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:30:58Z

Links: CVE-2026-75516 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling