CyberRota Analysis
AI-GeneratedThe RabbitMQ Java client library prior to version 5.37.0 is vulnerable due to a flaw in the JSON parsing mechanism, which can lead to denial of service (DoS) by exhausting heap memory or causing high CPU consumption. Applications using this library for JSON-RPC message handling should prioritize upgrading to version 5.37.0 to mitigate the risk of service interruptions. Organizations relying on Java and JVM-based applications that interact with RabbitMQ should assess their deployments for this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)