Skip to main content

Improper Input Validation in com.rabbitmq:amqp-client

CVE-2026-63335

  • com.rabbitmq:amqp-client
Severity Medium
Score 6.3/10

Summary

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to version 5.31.0, inbound AMQP command assembly in `src/main/java/com/rabbitmq/client/impl/CommandAssembler.java` processes a content-bearing method and header whose `remainingBodyBytes` value is smaller than a following `AMQP.FRAME_BODY` payload. `CommandAssembler.consumeBodyFrame` subtracts the peer-controlled payload length before validating that it fits, drives `remainingBodyBytes` negative, and throws a raw `UnsupportedOperationException` instead of `MalformedFrameException`. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.

  • LOW
  • NETWORK
  • NONE
  • LOW

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Advisory Timeline

  • Published