{"id":"CVE-2026-69219","aliases":["GHSA-68mj-5wr7-6fgg"],"url":"https://o3.security/vulnerability/CVE-2026-69219","summary":"RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation","details":"## Summary\n\n`ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.\n\n## Vulnerable Code\n\n`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 83-95:\n\n```java\nprivate static byte[] readBytes(final DataInputStream in) throws IOException {\n    final long contentLength = unsignedExtend(in.readInt());\n    if(contentLength < Integer.MAX_VALUE) {\n        final byte[] buffer = new byte[(int)contentLength];  // allocates before reading\n        in.readFully(buffer);\n        return buffer;\n    }\n}\n```\n\n## Attack Scenario\n\nA malicious AMQP server sends a LongString field (type tag 'S') with declared length `0x7FFFFFFE` (2,147,483,646). The check `contentLength < Integer.MAX_VALUE` passes. `new byte[2147483646]` attempts ~2GB allocation, causing `OutOfMemoryError` before `readFully()` attempts to read data.\n\nThe allocation size is attacker-controlled and is NOT validated against the frame size or `TruncatedInputStream` bounds. Exploitable pre-authentication via `connection.start` server-properties table.\n\n## Impact\n\nDenial of service via JVM `OutOfMemoryError`. Crashes the entire JVM.\n\n## CWE\n\nCWE-789: Memory Allocation with Excessive Size Value\n\n## Remediation\n\nValidate `contentLength` against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.","published":"2026-08-18T16:23:32.097Z","modified":"2026-09-20T14:13:53.317080Z","cvss":null,"epss":{"score":0.00422,"percentile":0.35919,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.rabbitmq:amqp-client","fixedVersion":"5.33.1"}],"fix":{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0","label":"rabbitmq/rabbitmq-java-client@3882093"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69219.json"},{"type":"ADVISORY","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69219"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/388209356c6478088efce4d8a07b68e73837a7a0"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2007"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2008"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-20T14:13:53.317080Z"}}