#1149675 rabbitmq-java-client: CVE-2026-75516

Package:
src:rabbitmq-java-client
Source:
src:rabbitmq-java-client
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 07:39:17 UTC
Severity:
normal
Tags:
#1149675#5
Date:
2026-10-02 07:23:23 UTC
From:
To:
Hi,

The following vulnerability was published for rabbitmq-java-client.

CVE-2026-75516[0]:
| The RabbitMQ Java client library allows Java and JVM-based
| applications to connect to and interact with RabbitMQ nodes. Prior
| to 5.34.0, AMQConnection.start() applies
| Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune
| negotiation even though AMQP defines frameMax value zero as
| unlimited and ConnectionFactory.DEFAULT_FRAME_MAX is zero. When the
| client default and server-negotiated value are both zero, the result
| is passed to Utils.framePayloadLimit(int), which interprets zero as
| Integer.MAX_VALUE and disables the configured
| maxInboundMessageBodySize cap. A malicious AMQP server, or a man-in-
| the-middle attacker able to modify Connection.Tune and inject frames
| into the connection, can then send an oversized frame of any frame
| type, causing Frame.readFrom() to allocate a large byte array before
| content-level validation and potentially terminate the client
| process through memory exhaustion. This issue is fixed in version
| 5.34.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75516
https://www.cve.org/CVERecord?id=CVE-2026-75516
[1] https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-jh4v-gfqj-7rhx
[2] https://github.com/rabbitmq/rabbitmq-java-client/pull/2015
[3] https://github.com/rabbitmq/rabbitmq-java-client/pull/2016
[4] https://github.com/rabbitmq/rabbitmq-java-client/commit/e7f10bf99aee103dd9f64b3e52a725fc9f9d3763

Regards,
Salvatore