Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-93j5-89vc-pph4 | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS |
Tue, 18 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1. | |
| Title | RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS | |
| Weaknesses | CWE-674 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T17:45:59.023Z
Reserved: 2026-08-03T16:57:50.125Z
Link: CVE-2026-69220
No data.
Status : Received
Published: 2026-08-18T17:17:01.497
Modified: 2026-08-18T18:19:28.640
Link: CVE-2026-69220
No data.
OpenCVE Enrichment
Updated: 2026-08-18T17:30:15Z
Github GHSA