<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:19:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355090</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355090</link>
      <description>EUVD-2026-355090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355090</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63335</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63335</link>
      <description>&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63335</guid>
    </item>
    <item>
      <title>GHSA-qx7j-jv8m-fppr — RabbitMQ Java client malformed body frame triggers raw command assembler exception</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qx7j-jv8m-fppr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.rabbitmq:amqp-client&lt;/p&gt;
&lt;p&gt;### Summary
RabbitMQ Java Client&amp;#39;s inbound AMQP command assembly accepts a content header declaring a small body and then processes a larger body frame by throwing a raw `UnsupportedOperationException` from `CommandAssembler`. A broker peer that the client has connected to can use this malformed frame sequence to fail frame processing and tear down the client connection instead of receiving a clean protocol-level malformed-frame error.&lt;/p&gt;
&lt;p&gt;This was discovered based on an existing vulnerability CVE-2017-15699.&lt;/p&gt;
&lt;p&gt;### Details
Inbound frames enter the client through `SocketFrameHandler.readFrame`, which returns frames parsed from the peer-controlled input stream (`src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java:197`). `AMQConnection.MainLoop` reads each frame (`src/main/java/com/rabbitmq/client/impl/AMQConnection.java:692`) and dispatches non-zero-channel frames to the channel while the connection is open (`src/main/java/com/rabbitmq/client/impl/AMQConnection.java:748` and `src/main/java/com/rabbitmq/client/impl/AMQConnection.java:766`). The channel then passes the frame to the current command assembler through `AMQChannel.handleFrame` and `AMQCommand.handleFrame` (`src/main/java/com/rabbitmq/client/impl/AMQChannel.java:121`, `src/main/java/com/rabbitmq/client/impl/AMQCommand.java:114`). When a content-bearing method is followed by a content header, `CommandAssembler.consumeHeaderFrame` records the header&amp;#39;s declared body size in `remainingBodyBytes` after only checki…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.rabbitmq:amqp-client&lt;/p&gt;
&lt;p&gt;### Summary
RabbitMQ Java Client&amp;#39;s inbound AMQP command assembly accepts a content header declaring a small body and then processes a larger body frame by throwing a raw `UnsupportedOperationException` from `CommandAssembler`. A broker peer that the client has connected to can use this malformed frame sequence to fail frame processing and tear down the client connection instead of receiving a clean protocol-level malformed-frame error.&lt;/p&gt;
&lt;p&gt;This was discovered based on an existing vulnerability CVE-2017-15699.&lt;/p&gt;
&lt;p&gt;### Details
Inbound frames enter the client through `SocketFrameHandler.readFrame`, which returns frames parsed from the peer-controlled input stream (`src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java:197`). `AMQConnection.MainLoop` reads each frame (`src/main/java/com/rabbitmq/client/impl/AMQConnection.java:692`) and dispatches non-zero-channel frames to the channel while the connection is open (`src/main/java/com/rabbitmq/client/impl/AMQConnection.java:748` and `src/main/java/com/rabbitmq/client/impl/AMQConnection.java:766`). The channel then passes the frame to the current command assembler through `AMQChannel.handleFrame` and `AMQCommand.handleFrame` (`src/main/java/com/rabbitmq/client/impl/AMQChannel.java:121`, `src/main/java/com/rabbitmq/client/impl/AMQCommand.java:114`). When a content-bearing method is followed by a content header, `CommandAssembler.consumeHeaderFrame` records the header&amp;#39;s declared body size in `remainingBodyBytes` after only checki…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qx7j-jv8m-fppr</guid>
    </item>
    <item>
      <title>OESA-2026-4112 — rabbitmq-java-client security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: rabbitmq-java-client, openEuler:24.03-LTS-SP4: rabbitmq-java-client, openEuler:20.03-LTS-SP4: rabbitmq-java-client, openEuler:22.03-LTS-SP4: rabbitmq-java-client, openEuler:24.03-LTS-SP1: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The library allows Java code to interface to AMQP servers. Please see the specification page for more information on AMQP inter-operation and standards-conformance You will need an AMQP server, such as our very own RabbitMQ server, to use with the client library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.(CVE-2023-46120)&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with Ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: rabbitmq-java-client, openEuler:24.03-LTS-SP4: rabbitmq-java-client, openEuler:20.03-LTS-SP4: rabbitmq-java-client, openEuler:22.03-LTS-SP4: rabbitmq-java-client, openEuler:24.03-LTS-SP1: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The library allows Java code to interface to AMQP servers. Please see the specification page for more information on AMQP inter-operation and standards-conformance You will need an AMQP server, such as our very own RabbitMQ server, to use with the client library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.(CVE-2023-46120)&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with Ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4112</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63335</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63335</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rabbitmq-java-client, Ubuntu:20.04:LTS: rabbitmq-java-client, Ubuntu:22.04:LTS: rabbitmq-java-client, Ubuntu:24.04:LTS: rabbitmq-java-client, Ubuntu:26.04:LTS: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rabbitmq-java-client, Ubuntu:20.04:LTS: rabbitmq-java-client, Ubuntu:22.04:LTS: rabbitmq-java-client, Ubuntu:24.04:LTS: rabbitmq-java-client, Ubuntu:26.04:LTS: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller than a following AMQP.FRAME_BODY payload. CommandAssembler.consumeBodyFrame subtracts the peer-controlled payload length before validating that it fits, drives remainingBodyBytes negative, and throws a raw UnsupportedOperationException instead of MalformedFrameException. A malicious or compromised broker peer can send this malformed sequence on an open nonzero channel to terminate frame processing and close the client connection, causing denial of service for work using that connection. This issue is fixed in version 5.31.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63335</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2921 — RabbitMQ Java Client: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2921</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im RabbitMQ Java Client ausnutzen, um Code auszuführen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im RabbitMQ Java Client ausnutzen, um Code auszuführen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2921</guid>
    </item>
  </channel>
</rss>
