DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-106121: CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

Vulnerability ID: CVE-2026-106121
CVSS Score: 4.9
Published: 2026-10-07

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

TL;DR

A Denial of Service vulnerability in RabbitMQ Java Client's legacy JSON reader permits authenticated attackers to trigger 100% CPU exhaustion or JVM OutOfMemoryError crashes by sending malformed or truncated JSON payloads.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-835
  • Attack Vector: Network
  • CVSS v3.1 Score: 4.9 (Medium)
  • EPSS Score: 0.00493 (Percentile: 40.36%)
  • Impact: Denial of Service (CPU Starvation / JVM Crash)
  • Exploit Status: Proof-of-Concept Available
  • CISA KEV Status: Not Listed

Affected Systems

  • JVM applications using the legacy JSON-RPC server mapper (DefaultJsonRpcMapper) in RabbitMQ Java Client
  • RabbitMQ Java Client (com.rabbitmq:amqp-client)
  • amqp-client: >= 5.19.0, < 5.37.0 (Fixed in: 5.37.0)

Code Analysis

Commit: 25fad81

Fix infinite loop in JSONReader parsing truncated inputs and harden JsonRpcServer runtime exception handling

Exploit Details

  • GitHub Security Advisory: Exploit concepts details including malformed payloads trigger CPU starvation and JVM OutOfMemory crashes.

Mitigation Strategies

  • Upgrade the com.rabbitmq:amqp-client library dependency to version 5.37.0 or higher.
  • Migrate from the deprecated DefaultJsonRpcMapper to the Jackson-based JacksonJsonRpcMapper.
  • Deploy Web Application Firewall (WAF) or security filter rules to reject truncated JSON payloads or trailing comments.

Remediation Steps:

  1. Identify all Java and Kotlin projects utilizing the com.rabbitmq:amqp-client or rabbitmq-java-client library.
  2. Update the build configuration (pom.xml for Maven, build.gradle for Gradle) to specify version 5.37.0 or above.
  3. In codebase configurations where JsonRpcServer is initialized, locate usages of DefaultJsonRpcMapper and instantiate JacksonJsonRpcMapper instead.
  4. Run unit and integration test suites to verify compatibility with the upgraded library and the alternate JSON mapper.
  5. Deploy the patched application to staging and production environments, monitoring CPU usage and heap allocation metrics.

References


Read the full report for CVE-2026-106121 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)