CVE-2026-69220: Rabbitmq Rabbitmq-Java-Client
High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.
Affected products
- Rabbitmq Rabbitmq-Java-Client: before 5.33.1 (fixed in 5.33.1)
Published 2026-08-18. Last modified 2026-09-10.