{"id":"CVE-2026-61634","aliases":["GHSA-5xwg-cfvj-gff5"],"url":"https://o3.security/vulnerability/CVE-2026-61634","summary":"RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max","details":"The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with MalformedFrameException. The protocol violation can disrupt the affected connection and cause client-side denial of service. This issue is fixed in version 5.33.0.","published":"2026-08-18T16:32:19.602Z","modified":"2026-08-19T15:41:56.968947728Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"com.rabbitmq:amqp-client","fixedVersion":"5.33.0"}],"fix":{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591","label":"rabbitmq/rabbitmq-java-client@08790f0"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61634.json"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/1994"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/1995"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0"},{"type":"ADVISORY","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61634"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T15:41:56.968947728Z"}}