Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-69220

Опубликовано: 18 авг. 2026
Источник: nvd
EPSS Низкий

Описание

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.

EPSS

Процентиль: 33%
0.00399
Низкий

Дефекты

CWE-674

Связанные уязвимости

ubuntu
13 дней назад

(The RabbitMQ Java client library allows Java and JVM-based application ...)

debian
13 дней назад

The RabbitMQ Java client library allows Java and JVM-based application ...

github
13 дней назад

RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS

EPSS

Процентиль: 33%
0.00399
Низкий

Дефекты

CWE-674