Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93j5-89vc-pph4

Опубликовано: 18 авг. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

Summary

ValueReader.readTable() and readArray() recursively call readFieldValue() with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.

Vulnerable Code

src/main/java/com/rabbitmq/client/impl/ValueReader.java lines 139-155 and 237-249:

private static Map<String, Object> readTable(DataInputStream in) throws IOException { long tableLength = unsignedExtend(in.readInt()); // ... while(tableIn.available() > 0) { String name = readShortstr(tableIn); Object value = readFieldValue(tableIn); // recursive call } } static Object readFieldValue(DataInputStream in) throws IOException { switch(in.readUnsignedByte()) { case 'F': value = readTable(in); // mutual recursion case 'A': value = readArray(in); // mutual recursion } }

Attack Scenario

A malicious AMQP server (or MitM) sends a connection.start frame with ~580 levels of nested tables. Each level costs ~7 bytes (4-byte length + 1-byte key length + 1-byte key + 1-byte type tag), totaling ~4060 bytes within the 131,072 byte max frame size. With the default JVM stack (~512KB, ~864 bytes/frame), this triggers StackOverflowError, killing the I/O thread.

Exploitable pre-authentication since connection.start is the very first server frame.

Impact

Denial of service. StackOverflowError kills the client I/O thread.

CWE

CWE-674: Uncontrolled Recursion

Remediation

Add a depth counter to readTable/readArray/readFieldValue and throw MalformedFrameException when exceeding a threshold (e.g., 32).

Пакеты

Наименование

com.rabbitmq:amqp-client

maven
Затронутые версииВерсия исправления

<= 5.33.0

5.33.1

EPSS

Процентиль: 33%
0.00399
Низкий

8.7 High

CVSS4

Дефекты

CWE-674

Связанные уязвимости

ubuntu
13 дней назад

(The RabbitMQ Java client library allows Java and JVM-based application ...)

nvd
13 дней назад

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.

debian
13 дней назад

The RabbitMQ Java client library allows Java and JVM-based application ...

EPSS

Процентиль: 33%
0.00399
Низкий

8.7 High

CVSS4

Дефекты

CWE-674