CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser
Vulnerability ID: CVE-2026-106121
CVSS Score: 4.9
Published: 2026-10-07
CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.
TL;DR
A Denial of Service vulnerability in RabbitMQ Java Client's legacy JSON reader permits authenticated attackers to trigger 100% CPU exhaustion or JVM OutOfMemoryError crashes by sending malformed or truncated JSON payloads.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-835
- Attack Vector: Network
- CVSS v3.1 Score: 4.9 (Medium)
- EPSS Score: 0.00493 (Percentile: 40.36%)
- Impact: Denial of Service (CPU Starvation / JVM Crash)
- Exploit Status: Proof-of-Concept Available
- CISA KEV Status: Not Listed
Affected Systems
- JVM applications using the legacy JSON-RPC server mapper (DefaultJsonRpcMapper) in RabbitMQ Java Client
- RabbitMQ Java Client (com.rabbitmq:amqp-client)
-
amqp-client: >= 5.19.0, < 5.37.0 (Fixed in:
5.37.0)
Code Analysis
Commit: 25fad81
Fix infinite loop in JSONReader parsing truncated inputs and harden JsonRpcServer runtime exception handling
Exploit Details
- GitHub Security Advisory: Exploit concepts details including malformed payloads trigger CPU starvation and JVM OutOfMemory crashes.
Mitigation Strategies
- Upgrade the com.rabbitmq:amqp-client library dependency to version 5.37.0 or higher.
- Migrate from the deprecated DefaultJsonRpcMapper to the Jackson-based JacksonJsonRpcMapper.
- Deploy Web Application Firewall (WAF) or security filter rules to reject truncated JSON payloads or trailing comments.
Remediation Steps:
- Identify all Java and Kotlin projects utilizing the com.rabbitmq:amqp-client or rabbitmq-java-client library.
- Update the build configuration (pom.xml for Maven, build.gradle for Gradle) to specify version 5.37.0 or above.
- In codebase configurations where JsonRpcServer is initialized, locate usages of DefaultJsonRpcMapper and instantiate JacksonJsonRpcMapper instead.
- Run unit and integration test suites to verify compatibility with the upgraded library and the alternate JSON mapper.
- Deploy the patched application to staging and production environments, monitoring CPU usage and heap allocation metrics.
References
- CVE-2026-106121 CVE Record
- NVD CVE-2026-106121
- GitHub Security Advisory GHSA-cqgh-8p3p-mx4m
- Official Fix Commit 25fad817
- Hardening Pull Request #2100
- RabbitMQ Java Client v5.37.0 Release Tag
Read the full report for CVE-2026-106121 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)