Denial of Service Vulnerability in RabbitMQ Java Client Library
CVE-2026-61634
NONE
What is CVE-2026-61634?
The RabbitMQ Java client library, utilized by Java and JVM-based applications for connecting to RabbitMQ nodes, has a vulnerability that allows a malicious broker to exploit the AMQP connection tuning path. Before version 5.33.0, inconsistencies in frame payload validation could permit a broker to send oversized method frames during or post connection establishment, leading the client to decode these invalid frames. This results in protocol violations that disrupt connections, potentially causing client-side denial of service scenarios. The issue has been rectified in version 5.33.0.
Affected Version(s)
rabbitmq-java-client < 5.33.0
