Vulnerability GHSA-6g32-pxv4-2wfj

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 month ago
August 18, 2026 at 04:32 PM UTC
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0

Summary

RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading

Details

The JSON-RPC tools in com.rabbitmq.tools.jsonrpc perform Class.forName(javaReturnType) with initialize=true on class names received from untrusted AMQP messages, without any validation or allowlist.

Vulnerable code (ProcedureDescription.java:101-127): When a JsonRpcClient connects, it calls system.describe and receives a service description from the AMQP queue. The response JSON includes javaReturnType fields that are reflectively set via JSONUtil.tryFill(), triggering setJavaReturnType() → computeReturnTypeAsJavaClass() → Class.forName(javaReturnType).

Attack scenario:

  1. Victim uses JsonRpcClient to connect to a JSON-RPC service via RabbitMQ
  2. Attacker (co-tenant on shared broker, or MITM) intercepts the system.describe request
  3. Attacker responds with crafted javaReturnType values
  4. Victim's client calls Class.forName(attackerInput) with default initialize=true
  5. Static initializers of attacker-specified classes execute in victim's JVM

Additionally, the loaded class from getReturnType() is passed to mapper.parse(replyStr, expectedType) at JsonRpcClient.java:168, potentially enabling type-confusion.

Recommended fix: Use Class.forName(javaReturnType, false, classLoader) to prevent static initializer execution, or add an allowlist of permitted return types.

CWE: CWE-470

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 hours ago
RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.34.0 GHSA-h6w7-qmcm-q6xr
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.34.0 GHSA-h6w7-qmcm-q6xr
High Risk
20 days ago
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.33.1 GHSA-jh4v-gfqj-7rhx
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.33.1 GHSA-jh4v-gfqj-7rhx
Low Risk
1 month ago
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5xwg-cfvj-gff5
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5xwg-cfvj-gff5
Medium Risk
1 month ago
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5m9f-rphj-c435
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5m9f-rphj-c435
Medium Risk
1 month ago
RabbitMQ Java client malformed body frame triggers raw command assembler exception
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.30.0 GHSA-qx7j-jv8m-fppr
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.30.0 GHSA-qx7j-jv8m-fppr
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
1 month ago
August 18, 2026 at 04:32 PM UTC
Fixed (5.33.0)
Unknown
Unknown
Last Modified
27 days ago
September 10, 2026 at 03:51 AM UTC