CVE-2026-75516
RabbitMQ Java client loses its inbound message size cap when frameMax is zero
Technology
RabbitMQ
CVSS Score
8.7 / 10.0
Affected Versions
RabbitMQ Java client before 5.34.0
Upstream Fix
RabbitMQ Java client 5.34.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
After Connection.Tune, AMQConnection.start() takes the minimum of maxInboundMessageBodySize and frameMax, but AMQP treats a frameMax of zero as unlimited and zero is the client default. When both sides use zero, the configured size cap is disabled, and a malicious server or an on-path attacker who can alter the tune and inject frames can send an oversized frame that is allocated in full, which can exhaust memory and end the client process.
Is your RabbitMQ deployment affected?
If you're running RabbitMQ Java client before 5.34.0, you need this patch. Book a discovery call to get covered.