Feed/CVE-2026-69219
CVE-2026-69219HIGHCVSS 0.0

RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation

Published Aug 18, 2026·Updated Aug 18, 2026

NVD Description

## Summary `ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field. ## Vulnerable Code `src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 83-95: ```java private static byte[] readBytes(final DataInputStream in) throws IOException { final long contentLength = unsignedExtend(in.readInt()); if(contentLength < Integer.MAX_VALUE) { final byte[] buffer = new byte[(int)contentLength]; // allocates before reading in.readFully(buffer); return buffer; } } ``` ## Attack Scenario A malicious AMQP server sends a LongString field (type tag 'S') with declared length `0x7FFFFFFE` (2,147,483,646). The check `contentLength < Integer.MAX_VALUE` passes. `new byte[2147483646]` attempts ~2GB allocation, causing `OutOfMemoryError` before `readFully()` attempts to read data. The allocation size is attacker-controlled and is NOT validated against the frame size or `TruncatedInputStream` bounds. Exploitable pre-authentication via `connection.start` server-properties table. ## Impact Denial of service via JVM `OutOfMemoryError`. Crashes the entire JVM. ## CWE CWE-789: Memory Allocation with Excessive Size Value ## Remediation Validate `contentLength` against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.

Affected Packages (1)

com.rabbitmq:amqp-clientMAVEN
Fixed in = 5.33.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free