Allocation of Resources Without Limits or Throttling Affecting com.rabbitmq:amqp-client package, versions [,5.34.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.53% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-COMRABBITMQ-19963954
  • published20 Sept 2026
  • disclosed17 Sept 2026
  • creditlucianjohnhouse

Introduced: 17 Sep 2026

NewCVE-2026-75516  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade com.rabbitmq:amqp-client to version 5.34.0 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the inbound frame size handling in AMQConnection.java. An attacker can trigger excessive frame allocation and crash the client by negotiating frame_max=0 and then sending an oversized AMQP frame. The vulnerable code derives the inbound frame payload limit with Math.min(this.maxInboundMessageBodySize, frameMax), so a negotiated zero-valued frameMax is treated as a literal limit of 0 and defeats the configured inbound cap. Because frame.readFrom() allocates based on that effective limit, a malicious broker or MITM can force the client to accept a huge frame and exhaust memory during connection processing.

CVSS Base Scores

version 4.0
version 3.1