SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-69220

HIGH · CVSS 8.7 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RabbitMQ Java client library prior to version 5.33.1 is vulnerable to a denial-of-service attack due to an unchecked recursion in the handling of AMQP table and array types, allowing a malicious actor to exploit this flaw by sending deeply nested structures. This can lead to a StackOverflowError, terminating the client input processing thread and disrupting service. Organizations using the RabbitMQ Java client should prioritize upgrading to version 5.33.1 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-69220
Severity
HIGH
CVSS
8.7
EPSS
0.40%
Java

Original NVD Description

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.