{"id":"CVE-2026-69219","title":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes","summary":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…","severity":"high","cwe":["CWE-789"],"vendor":"rabbitmq","product":"com.rabbitmq:amqp-client","affected":["com.rabbitmq:amqp-client <= 5.33.0"],"patched":["com.rabbitmq:amqp-client 5.33.1"],"published":"2026-08-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:05:53.723","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69219","references":[{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2007","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2008","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.1","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-68mj-5wr7-6fgg"}],"tags":["nvd","ghsa","maven"],"epss":0.00422,"epssPercentile":0.36047,"aliases":["GHSA-68mj-5wr7-6fgg"],"ecosystem":"maven","ingestedAt":"2026-08-18T17:20:36.621Z","slug":"CVE-2026-69219","body":"## Overview\n\nThe RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before checking the bytes available in the frame. A malicious AMQP peer can send a LongString or byte-array field with type tag S and a declared length such as 0x7FFFFFFE during the pre-authentication connection.start server-properties table, causing an approximately 2 GB allocation and OutOfMemoryError before readFully consumes data. The resulting memory exhaustion can terminate the JVM and cause denial of service. This issue is fixed in version 5.33.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-69219)\n\nAffected packages:\n\n- `com.rabbitmq:amqp-client <= 5.33.0`\n\nPatched in:\n\n- `com.rabbitmq:amqp-client 5.33.1`\n\nSource: https://github.com/advisories/GHSA-68mj-5wr7-6fgg","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}