{"id":"CVE-2026-69220","aliases":["GHSA-93j5-89vc-pph4"],"url":"https://o3.security/vulnerability/CVE-2026-69220","summary":"RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS","details":"## Summary\n\n`ValueReader.readTable()` and `readArray()` recursively call `readFieldValue()` with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.\n\n## Vulnerable Code\n\n`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 139-155 and 237-249:\n\n```java\nprivate static Map<String, Object> readTable(DataInputStream in) throws IOException {\n    long tableLength = unsignedExtend(in.readInt());\n    // ...\n    while(tableIn.available() > 0) {\n        String name = readShortstr(tableIn);\n        Object value = readFieldValue(tableIn);  // recursive call\n    }\n}\n\nstatic Object readFieldValue(DataInputStream in) throws IOException {\n    switch(in.readUnsignedByte()) {\n      case 'F': value = readTable(in);  // mutual recursion\n      case 'A': value = readArray(in);  // mutual recursion\n    }\n}\n```\n\n## Attack Scenario\n\nA malicious AMQP server (or MitM) sends a `connection.start` frame with ~580 levels of nested tables. Each level costs ~7 bytes (4-byte length + 1-byte key length + 1-byte key + 1-byte type tag), totaling ~4060 bytes within the 131,072 byte max frame size. With the default JVM stack (~512KB, ~864 bytes/frame), this triggers `StackOverflowError`, killing the I/O thread.\n\nExploitable pre-authentication since `connection.start` is the very first server frame.\n\n## Impact\n\nDenial of service. `StackOverflowError` kills the client I/O thread.\n\n## CWE\n\nCWE-674: Uncontrolled Recursion\n\n## Remediation\n\nAdd a depth counter to `readTable`/`readArray`/`readFieldValue` and throw `MalformedFrameException` when exceeding a threshold (e.g., 32).","published":"2026-08-18T16:25:16.178Z","modified":"2026-09-12T08:07:28.330955Z","cvss":null,"epss":{"score":0.00399,"percentile":0.33749,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.rabbitmq:amqp-client","fixedVersion":"5.33.1"}],"fix":{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0","label":"rabbitmq/rabbitmq-java-client@09af76f"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69220.json"},{"type":"ADVISORY","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-93j5-89vc-pph4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69220"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/db89e34809fbc6ba4e946615f297f3684ccd0acc"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2007"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2008"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T08:07:28.330955Z"}}