ghsa-68mj-5wr7-6fgg
CVSS 8.7 osv_maven## Summary `ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field. ## Vulnerable Code `src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 83-95: ```java private static byte[] readBytes(final DataInputStream in) throws IOException { final long contentLength = unsignedExtend(in.readInt()); if(contentLength < Integer.MAX_VALUE) { final byte[] buffer = new byte[(int)contentLength]; // allocates before reading in.readFully(buffer); return buffer; } } ``` ## Attack Scenario A malicious AMQP server sends a LongString field (type tag 'S') with declared length `0x7FFFFFFE` (2,147,483,646). The check `contentLength < Integer.MAX_VALUE` passes. `new byte[2147483646]` attempts ~2GB allocation, causing `OutOfMemoryError` before `readFully()` attempts to read data. The allocation size is attacker-controlled and is NOT validated against the frame size or `TruncatedInputStream` bounds. Exploitable pre-authentication via `connection.start` server-properties table. ## Impact Denial of service via JVM `OutOfMemoryError`. Crashes the entire JVM. ## CWE CWE-789: Memory Allocation with Excessive Size Value ## Remediation Validate `contentLength` against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2008
- https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0
- https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2
- https://github.com/rabbitmq/rabbitmq-java-client
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.1
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "<= 5.33.0",
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-68mj-5wr7-6fgg/GHSA-68mj-5wr7-6fgg.json"
},
"package": {
"ecosystem": "Maven",
"name": "com.rabbitmq:amqp-client",
"purl": "pkg:maven/com.rabbitmq/amqp-client"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.33.1"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.3.0",
"1.5.4",
"1.5.5",
"1.6.0",
"1.7.2",
"1.8.0",
"1.8.1",
"2.0.0",
"2.1.0",
"2.1.1",
"2.2.0",
"2.3.0",
"2.3.1",
"2.4.1",
"2.5.0",
"2.5.1",
"2.6.0",
"2.6.1",
"2.7.0",
"2.7.1",
"2.8.0",
"2.8.1",
"2.8.2",
"2.8.3",
"2.8.4",
"2.8.5",
"2.8.6",
"2.8.7",
"3.0.0",
"3.0.1",
"3.0.2",
"3.0.3",
"3.0.4",
"3.1.0",
"3.1.1",
"3.1.2",
"3.1.3",
"3.1.4",
"3.2.0",
"3.2.1",
"3.2.2",
"3.2.3",
"3.2.4",
"3.3.0",
"3.3.1",
"3.3.2",
"3.3.3",
"3.3.4",
"3.3.5",
"3.4.0",
"3.4.1",
"3.4.2",
"3.4.3",
"3.4.4",
"3.5.0",
"3.5.1",
"3.5.2",
"3.5.3",
"3.5.4",
"3.5.5",
"3.5.6",
"3.5.7",
"3.6.0",
"3.6.1",
"3.6.2",
"3.6.3",
"3.6.4",
"3.6.5",
"3.6.6",
"4.0.0",
"4.0.1",
"4.0.2",
"4.0.3",
"4.1.0",
"4.1.1",
"4.10.0",
"4.11.0",
"4.11.1",
"4.11.2",
"4.11.3",
"4.12.0",
"4.2.0",
"4.2.1",
"4.2.2",
"4.3.0",
"4.4.0",
"4.4.1",
"4.4.2",
"4.5.0",
"4.6.0",
"4.7.0",
"4.8.0",
"4.8.1",
"4.8.2",
"4.8.3",
"4.9.0",
"4.9.1",
"4.9.2",
"4.9.3",
"5.0.0",
"5.1.0",
"5.1.1",
"5.1.2",
"5.10.0",
"5.11.0",
"5.12.0",
"5.13.0",
"5.13.1",
"5.14.0",
"5.14.1",
"5.14.2",
"5.14.3",
"5.15.0",
"5.16.0",
"5.16.1",
"5.17.0",
"5.17.1",
"5.18.0",
"5.19.0",
"5.2.0",
"5.20.0",
"5.21.0",
"5.22.0",
"5.23.0",
"5.24.0",
"5.25.0",
"5.26.0",
"5.27.0",
"5.27.1",
"5.28.0",
"5.29.0",
"5.3.0",
"5.30.0",
"5.31.0",
"5.32.0",
"5.33.0",
"5.4.0",
"5.4.1",
"5.4.2",
"5.4.3",
"5.5.0",
"5.5.1",
"5.5.2",
"5.5.3",
"5.6.0",
"5.7.0",
"5.7.1",
"5.7.2",
"5.7.3",
"5.8.0",
"5.9.0"
]
}
],
"aliases": [
"CVE-2026-69219"
],
"database_specific": {
"cwe_ids": [
"CWE-789"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-18T16:32:20Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "## Summary\n\n`ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.\n\n## Vulnerable Code\n\n`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 83-95:\n\n```java\nprivate static byte[] readBytes(final DataInputStream in) throws IOException {\n final long contentLength = unsignedExtend(in.readInt());\n if(contentLength < Integer.MAX_VALUE) {\n final byte[] buffer = new byte[(int)contentLength]; // allocates before reading\n in.readFully(buffer);\n return buffer;\n }\n}\n```\n\n## Attack Scenario\n\nA malicious AMQP server sends a LongString field (type tag 'S') with declared length `0x7FFFFFFE` (2,147,483,646). The check `contentLength < Integer.MAX_VALUE` passes. `new byte[2147483646]` attempts ~2GB allocation, causing `OutOfMemoryError` before `readFully()` attempts to read data.\n\nThe allocation size is attacker-controlled and is NOT validated against the frame size or `TruncatedInputStream` bounds. Exploitable pre-authentication via `connection.start` server-properties table.\n\n## Impact\n\nDenial of service via JVM `OutOfMemoryError`. Crashes the entire JVM.\n\n## CWE\n\nCWE-789: Memory Allocation with Excessive Size Value\n\n## Remediation\n\nValidate `contentLength` against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.",
"id": "GHSA-68mj-5wr7-6fgg",
"modified": "2026-09-10T03:51:13.151154373Z",
"published": "2026-08-18T16:32:20Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/2007"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/2008"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2"
},
{
"type": "PACKAGE",
"url": "https://github.com/rabbitmq/rabbitmq-java-client"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.1"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation"
}