Denial of Service Vulnerability in RabbitMQ Java Client Library
CVE-2026-61634

NONE

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
18 August 2026

What is CVE-2026-61634?

The RabbitMQ Java client library, utilized by Java and JVM-based applications for connecting to RabbitMQ nodes, has a vulnerability that allows a malicious broker to exploit the AMQP connection tuning path. Before version 5.33.0, inconsistencies in frame payload validation could permit a broker to send oversized method frames during or post connection establishment, leading the client to decode these invalid frames. This results in protocol violations that disrupt connections, potentially causing client-side denial of service scenarios. The issue has been rectified in version 5.33.0.

Affected Version(s)

rabbitmq-java-client < 5.33.0

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.