Security: rabbitmq/rabbitmq-java-client
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()GHSA-h6w7-qmcm-q6xr published
Aug 21, 2026 by acogoluegnesModerate -
Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcementGHSA-jh4v-gfqj-7rhx published
Jul 10, 2026 by acogoluegnesHigh -
ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocationGHSA-68mj-5wr7-6fgg published
Jul 9, 2026 by ansdHigh -
ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoSGHSA-93j5-89vc-pph4 published
Jul 9, 2026 by ansdHigh -
Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loadingGHSA-6g32-pxv4-2wfj published
Jul 9, 2026 by ansdHigh -
TrustEverythingTrustManager used by default in useSslProtocol() enables MITMGHSA-5m9f-rphj-c435 published
Jul 9, 2026 by ansdModerate -
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxGHSA-5xwg-cfvj-gff5 published
Jul 9, 2026 by ansdLow -
RabbitMQ Java client malformed body frame triggers raw command assembler exceptionGHSA-qx7j-jv8m-fppr published
Jul 9, 2026 by ansdModerate -
No message size limit in RabbitMQ Java client can lead to a remote DoS attack of consumer applicationsGHSA-mm8h-8587-p46h published
Oct 23, 2023 by michaelklishinModerate