ghsa-5xwg-cfvj-gff5
osv_maven## Summary The max body size was enforced to patch CVE-2023-46120, but even though that limit still works, the frame size itself still exceeds the given max size. ## Root cause The Java client records the AMQP 0-9-1 `frame_max` negotiated during connection tuning, but the socket inbound frame reader continues to validate broker-controlled payload lengths against the much larger `maxInboundMessageBodySize` limit. A broker peer can therefore send a method frame whose payload is larger than the negotiated `frame_max`, have it allocated and decoded, and complete the connection handshake instead of being rejected as a protocol violation. *Reported by Team Atlanta.*
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
- https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
- https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
- https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591
- https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472
- https://github.com/rabbitmq/rabbitmq-java-client
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5xwg-cfvj-gff5/GHSA-5xwg-cfvj-gff5.json"
},
"package": {
"ecosystem": "Maven",
"name": "com.rabbitmq:amqp-client",
"purl": "pkg:maven/com.rabbitmq/amqp-client"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.33.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.3.0",
"1.5.4",
"1.5.5",
"1.6.0",
"1.7.2",
"1.8.0",
"1.8.1",
"2.0.0",
"2.1.0",
"2.1.1",
"2.2.0",
"2.3.0",
"2.3.1",
"2.4.1",
"2.5.0",
"2.5.1",
"2.6.0",
"2.6.1",
"2.7.0",
"2.7.1",
"2.8.0",
"2.8.1",
"2.8.2",
"2.8.3",
"2.8.4",
"2.8.5",
"2.8.6",
"2.8.7",
"3.0.0",
"3.0.1",
"3.0.2",
"3.0.3",
"3.0.4",
"3.1.0",
"3.1.1",
"3.1.2",
"3.1.3",
"3.1.4",
"3.2.0",
"3.2.1",
"3.2.2",
"3.2.3",
"3.2.4",
"3.3.0",
"3.3.1",
"3.3.2",
"3.3.3",
"3.3.4",
"3.3.5",
"3.4.0",
"3.4.1",
"3.4.2",
"3.4.3",
"3.4.4",
"3.5.0",
"3.5.1",
"3.5.2",
"3.5.3",
"3.5.4",
"3.5.5",
"3.5.6",
"3.5.7",
"3.6.0",
"3.6.1",
"3.6.2",
"3.6.3",
"3.6.4",
"3.6.5",
"3.6.6",
"4.0.0",
"4.0.1",
"4.0.2",
"4.0.3",
"4.1.0",
"4.1.1",
"4.10.0",
"4.11.0",
"4.11.1",
"4.11.2",
"4.11.3",
"4.12.0",
"4.2.0",
"4.2.1",
"4.2.2",
"4.3.0",
"4.4.0",
"4.4.1",
"4.4.2",
"4.5.0",
"4.6.0",
"4.7.0",
"4.8.0",
"4.8.1",
"4.8.2",
"4.8.3",
"4.9.0",
"4.9.1",
"4.9.2",
"4.9.3",
"5.0.0",
"5.1.0",
"5.1.1",
"5.1.2",
"5.10.0",
"5.11.0",
"5.12.0",
"5.13.0",
"5.13.1",
"5.14.0",
"5.14.1",
"5.14.2",
"5.14.3",
"5.15.0",
"5.16.0",
"5.16.1",
"5.17.0",
"5.17.1",
"5.18.0",
"5.19.0",
"5.2.0",
"5.20.0",
"5.21.0",
"5.22.0",
"5.23.0",
"5.24.0",
"5.25.0",
"5.26.0",
"5.27.0",
"5.27.1",
"5.28.0",
"5.29.0",
"5.3.0",
"5.30.0",
"5.31.0",
"5.32.0",
"5.4.0",
"5.4.1",
"5.4.2",
"5.4.3",
"5.5.0",
"5.5.1",
"5.5.2",
"5.5.3",
"5.6.0",
"5.7.0",
"5.7.1",
"5.7.2",
"5.7.3",
"5.8.0",
"5.9.0"
]
}
],
"aliases": [
"CVE-2026-61634"
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-18T16:36:29Z",
"nvd_published_at": null,
"severity": "LOW"
},
"details": "## Summary\nThe max body size was enforced to patch CVE-2023-46120, but even though that limit still works, the frame size itself still exceeds the given max size. \n\n## Root cause\nThe Java client records the AMQP 0-9-1 `frame_max` negotiated during connection tuning, but the socket inbound frame reader continues to validate broker-controlled payload lengths against the much larger `maxInboundMessageBodySize` limit. A broker peer can therefore send a method frame whose payload is larger than the negotiated `frame_max`, have it allocated and decoded, and complete the connection handshake instead of being rejected as a protocol violation.\n\n*Reported by Team Atlanta.*",
"id": "GHSA-5xwg-cfvj-gff5",
"modified": "2026-09-10T03:51:13.134044568Z",
"published": "2026-08-18T16:36:29Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/1994"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/1995"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472"
},
{
"type": "PACKAGE",
"url": "https://github.com/rabbitmq/rabbitmq-java-client"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max"
}