CVE-2026-106121
MEDIUM
4,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
835
Loop with Unreachable Exit Condition ('Infinite Loop')
IncompleteCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Amplification
Applicable Platforms
All platforms may be affected
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-cqgh-…
https://github.com/rabbitmq/rabbitmq-java-client/commit/25fad817291feff3195c326…
https://github.com/rabbitmq/rabbitmq-java-client/pull/2100
https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.37.0
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-cqgh-…