CyberRota Analysis
AI-GeneratedThe RabbitMQ Java client library prior to version 5.33.1 is vulnerable to a denial-of-service attack due to an unchecked recursion in the handling of AMQP table and array types, allowing a malicious actor to exploit this flaw by sending deeply nested structures. This can lead to a StackOverflowError, terminating the client input processing thread and disrupting service. Organizations using the RabbitMQ Java client should prioritize upgrading to version 5.33.1 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.