Vulnerability GHSA-qx7j-jv8m-fppr

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 18, 2026 at 04:32 PM UTC
RabbitMQ Java client malformed body frame triggers raw command assembler exception
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.30.0
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.30.0

Summary

RabbitMQ Java client malformed body frame triggers raw command assembler exception

Details

Summary

RabbitMQ Java Client's inbound AMQP command assembly accepts a content header declaring a small body and then processes a larger body frame by throwing a raw UnsupportedOperationException from CommandAssembler. A broker peer that the client has connected to can use this malformed frame sequence to fail frame processing and tear down the client connection instead of receiving a clean protocol-level malformed-frame error.

This was discovered based on an existing vulnerability CVE-2017-15699.

Details

Inbound frames enter the client through SocketFrameHandler.readFrame, which returns frames parsed from the peer-controlled input stream (src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java:197). AMQConnection.MainLoop reads each frame (src/main/java/com/rabbitmq/client/impl/AMQConnection.java:692) and dispatches non-zero-channel frames to the channel while the connection is open (src/main/java/com/rabbitmq/client/impl/AMQConnection.java:748 and src/main/java/com/rabbitmq/client/impl/AMQConnection.java:766). The channel then passes the frame to the current command assembler through AMQChannel.handleFrame and AMQCommand.handleFrame (src/main/java/com/rabbitmq/client/impl/AMQChannel.java:121, src/main/java/com/rabbitmq/client/impl/AMQCommand.java:114). When a content-bearing method is followed by a content header, CommandAssembler.consumeHeaderFrame records the header's declared body size in remainingBodyBytes after only checking it against the configured maximum (src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:126 through src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:139). The body-frame path subtracts the received payload length from that remaining count before validating that the payload fits (src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:145 through src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:149), so a body frame larger than the declared size drives the count negative and reaches the raw UnsupportedOperationException at src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:150 and src/main/java/com/rabbitmq/client/impl/CommandAssembler.java:151. AMQConnection catches the resulting throwable in frame processing and performs connection failure handling and final shutdown (src/main/java/com/rabbitmq/client/impl/AMQConnection.java:695 through src/main/java/com/rabbitmq/client/impl/AMQConnection.java:705).

PoC

poc.zip

bash ./poc/run.sh
Exception in thread "main" java.lang.UnsupportedOperationException: %%%%%% FIXME unimplemented

The UnsupportedOperationException: %%%%%% FIXME unimplemented fingerprint is the raw exception thrown at the negative remainingBodyBytes check in CommandAssembler.consumeBodyFrame. This line shows the malformed declared-size/body-size sequence reached the vulnerable assembler path.

Impact

The attacker model is a remote AMQP broker peer that the RabbitMQ Java Client application has accepted, including a malicious broker endpoint, a compromised broker, or routing that sends the client to an attacker-controlled peer. The peer needs a non-zero open channel that can receive a content-bearing server-to-client method such as basic.deliver, then sends the method frame, a content header declaring a body below the configured maximum, and a body frame whose payload exceeds that declared size. Under those conditions, the peer can force frame processing to fail with UnsupportedOperationException and close the AMQP connection, producing a client-side denial of service for work depending on that connection; the finding does not indicate memory corruption, data disclosure, or code execution.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 hours ago
RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.34.0 GHSA-h6w7-qmcm-q6xr
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.34.0 GHSA-h6w7-qmcm-q6xr
High Risk
20 days ago
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.33.1 GHSA-jh4v-gfqj-7rhx
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.33.1 GHSA-jh4v-gfqj-7rhx
Low Risk
1 month ago
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5xwg-cfvj-gff5
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5xwg-cfvj-gff5
Medium Risk
1 month ago
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5m9f-rphj-c435
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-5m9f-rphj-c435
High Risk
1 month ago
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-6g32-pxv4-2wfj
1.3.0 and 1.5.4 - 1.6.0 and 1.7.2 - 2.3.1 and 2.4.1 - 2.7.1 and 4.1.0 - 4.1.1 and 4.3.0 and 4.5.0 - 4.7.0 and 4.10.0 and 4.12.0 - 5.0.0 and 5.2.0 - 5.3.0 and 5.6.0 and 5.8.0 - 5.13.1 and 5.15.0 - 5.32.0 GHSA-6g32-pxv4-2wfj
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
1 month ago
August 18, 2026 at 04:32 PM UTC
Fixed (5.31.0)
Unknown
Unknown
Last Modified
27 days ago
September 10, 2026 at 03:50 AM UTC