AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106121.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

## Summary `com.rabbitmq.tools.json.JSONReader.read()` never returns when its input ends inside a quoted string or a `//` line comment. Both scanners walk the input with `StringCharacterIterator.next()` but only compare against a delimiter, so once the iterator reaches `CharacterIterator.DONE` (`￿`) they loop forever. The string scanner (`string()`, line 210, `while (c != sep)`) also appends `￿` to a `StringBuilder` every iteration, so it fills the heap and throws `OutOfMemoryError`, taking down the JVM. The comment scanner (`skipWhiteSpace()`, lines 89-92, `while (c != '\n')`) pins a thread at 100% CPU with no allocation. This is reachable with a single message. `JsonRpcServer` and `JsonRpcClient` fall back to `DefaultJsonRpcMapper` whenever no mapper is passed (`JsonRpcServer.java:84` and `:114`, `JsonRpcClient.java:186`), and that mapper hands the raw message body straight to `JSONReader.read()` (`DefaultJsonRpcMapper.java:42` for the server request, `:52` for the client reply). A caller that can publish to the RPC request queue hangs the server; a malicious or MITM'd JSON-RPC service does the same to a client. ## Proof of concept Against `amqp-client` 5.36.0 from Maven Central:

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-cqgh-8p3p-mx4m

Open original source · Updated Oct 07, 2026

RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
mavencom.rabbitmq:amqp-client5.36.1

Original records & references

PUBLISHED 2026-10-07T16:42:33-04:00
MODIFIED 2026-10-07T16:42:34-04:00
INGESTED 2026-10-08T12:30:44-04:00