<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:36:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355093</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355093</link>
      <description>EUVD-2026-355093</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355093</guid>
    </item>
    <item>
      <title>fkie_cve-2026-69220</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-69220</link>
      <description>&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-69220</guid>
    </item>
    <item>
      <title>GHSA-93j5-89vc-pph4 — RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-93j5-89vc-pph4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.rabbitmq:amqp-client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ValueReader.readTable()` and `readArray()` recursively call `readFieldValue()` with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 139-155 and 237-249:&lt;/p&gt;
&lt;p&gt;```java
private static Map&amp;lt;String, Object&amp;gt; readTable(DataInputStream in) throws IOException {
    long tableLength = unsignedExtend(in.readInt());
    // ...
    while(tableIn.available() &amp;gt; 0) {
        String name = readShortstr(tableIn);
        Object value = readFieldValue(tableIn);  // recursive call
    }
}&lt;/p&gt;
&lt;p&gt;static Object readFieldValue(DataInputStream in) throws IOException {
    switch(in.readUnsignedByte()) {
      case &amp;#39;F&amp;#39;: value = readTable(in);  // mutual recursion
      case &amp;#39;A&amp;#39;: value = readArray(in);  // mutual recursion
    }
}
```&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;A malicious AMQP server (or MitM) sends a `connection.start` frame with ~580 levels of nested tables. Each level costs ~7 bytes (4-byte length + 1-byte key length + 1-byte key + 1-byte type tag), totaling ~4060 bytes within the 131,072 byte max frame size. With the default JVM stack (~512KB, ~864 bytes/frame), this triggers `StackOverflowError`, killing the I/O thread.&lt;/p&gt;
&lt;p&gt;Exploitable pre-authentication since `connection.start` is the very first server frame.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Denial of service. `StackOverflowError` kills the client I/O thread.&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;CWE-674: Uncontrolled Recursion&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;Add a depth c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.rabbitmq:amqp-client&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`ValueReader.readTable()` and `readArray()` recursively call `readFieldValue()` with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.&lt;/p&gt;
&lt;p&gt;## Vulnerable Code&lt;/p&gt;
&lt;p&gt;`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 139-155 and 237-249:&lt;/p&gt;
&lt;p&gt;```java
private static Map&amp;lt;String, Object&amp;gt; readTable(DataInputStream in) throws IOException {
    long tableLength = unsignedExtend(in.readInt());
    // ...
    while(tableIn.available() &amp;gt; 0) {
        String name = readShortstr(tableIn);
        Object value = readFieldValue(tableIn);  // recursive call
    }
}&lt;/p&gt;
&lt;p&gt;static Object readFieldValue(DataInputStream in) throws IOException {
    switch(in.readUnsignedByte()) {
      case &amp;#39;F&amp;#39;: value = readTable(in);  // mutual recursion
      case &amp;#39;A&amp;#39;: value = readArray(in);  // mutual recursion
    }
}
```&lt;/p&gt;
&lt;p&gt;## Attack Scenario&lt;/p&gt;
&lt;p&gt;A malicious AMQP server (or MitM) sends a `connection.start` frame with ~580 levels of nested tables. Each level costs ~7 bytes (4-byte length + 1-byte key length + 1-byte key + 1-byte type tag), totaling ~4060 bytes within the 131,072 byte max frame size. With the default JVM stack (~512KB, ~864 bytes/frame), this triggers `StackOverflowError`, killing the I/O thread.&lt;/p&gt;
&lt;p&gt;Exploitable pre-authentication since `connection.start` is the very first server frame.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Denial of service. `StackOverflowError` kills the client I/O thread.&lt;/p&gt;
&lt;p&gt;## CWE&lt;/p&gt;
&lt;p&gt;CWE-674: Uncontrolled Recursion&lt;/p&gt;
&lt;p&gt;## Remediation&lt;/p&gt;
&lt;p&gt;Add a depth c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-93j5-89vc-pph4</guid>
    </item>
    <item>
      <title>OESA-2026-4112 — rabbitmq-java-client security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4112</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: rabbitmq-java-client, openEuler:24.03-LTS-SP4: rabbitmq-java-client, openEuler:20.03-LTS-SP4: rabbitmq-java-client, openEuler:22.03-LTS-SP4: rabbitmq-java-client, openEuler:24.03-LTS-SP1: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The library allows Java code to interface to AMQP servers. Please see the specification page for more information on AMQP inter-operation and standards-conformance You will need an AMQP server, such as our very own RabbitMQ server, to use with the client library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.(CVE-2023-46120)&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with Ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: rabbitmq-java-client, openEuler:24.03-LTS-SP4: rabbitmq-java-client, openEuler:20.03-LTS-SP4: rabbitmq-java-client, openEuler:22.03-LTS-SP4: rabbitmq-java-client, openEuler:24.03-LTS-SP1: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The library allows Java code to interface to AMQP servers. Please see the specification page for more information on AMQP inter-operation and standards-conformance You will need an AMQP server, such as our very own RabbitMQ server, to use with the client library.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer. This vulnerability was patched in version 5.18.0.(CVE-2023-46120)&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue to validate broker-controlled frame payload lengths against maxInboundMessageBodySize because the negotiated limit is not applied consistently through setMaxInboundFramePayloadSize. A malicious or compromised broker can send a method frame larger than the negotiated frame_max during or after connection establishment, causing the client to allocate and decode a protocol-invalid frame instead of rejecting it with Ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4112</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-69220</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69220</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rabbitmq-java-client, Ubuntu:20.04:LTS: rabbitmq-java-client, Ubuntu:22.04:LTS: rabbitmq-java-client, Ubuntu:24.04:LTS: rabbitmq-java-client, Ubuntu:26.04:LTS: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: rabbitmq-java-client, Ubuntu:20.04:LTS: rabbitmq-java-client, Ubuntu:22.04:LTS: rabbitmq-java-client, Ubuntu:24.04:LTS: rabbitmq-java-client, Ubuntu:26.04:LTS: rabbitmq-java-client&lt;/p&gt;
&lt;p&gt;The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F and AMQP array type A values without a nesting-depth limit. A malicious AMQP server or network intermediary can send approximately 580 nested table levels in the pre-authentication connection.start frame, fitting within the default 131072-byte frame maximum, to trigger StackOverflowError. The error terminates the client input processing thread and causes denial of service. This issue is fixed in version 5.33.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-69220</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2921 — RabbitMQ Java Client: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2921</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im RabbitMQ Java Client ausnutzen, um Code auszuführen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im RabbitMQ Java Client ausnutzen, um Code auszuführen, um Sicherheitsmechanismen zu umgehen und um einen Denial of Service herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2921</guid>
    </item>
  </channel>
</rss>
