Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-75516

RabbitMQ Java client loses its inbound message size cap when frameMax is zero

Technology

RabbitMQ

CVSS Score

8.7 / 10.0

Affected Versions

RabbitMQ Java client before 5.34.0

Upstream Fix

RabbitMQ Java client 5.34.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

After Connection.Tune, AMQConnection.start() takes the minimum of maxInboundMessageBodySize and frameMax, but AMQP treats a frameMax of zero as unlimited and zero is the client default. When both sides use zero, the configured size cap is disabled, and a malicious server or an on-path attacker who can alter the tune and inject frames can send an oversized frame that is allocated in full, which can exhaust memory and end the client process.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running RabbitMQ Java client before 5.34.0, you need this patch. Book a discovery call to get covered.