Disclosure summary
## Summary `com.rabbitmq.tools.json.JSONReader.read()` never returns when its input ends inside a quoted string or a `//` line comment. Both scanners walk the input with `StringCharacterIterator.next()` but only compare against a delimiter, so once the iterator reaches `CharacterIterator.DONE` (``) they loop forever. The string scanner (`string()`, line 210, `while (c != sep)`) also appends `` to a `StringBuilder` every iteration, so it fills the heap and throws `OutOfMemoryError`, taking down the JVM. The comment scanner (`skipWhiteSpace()`, lines 89-92, `while (c != '\n')`) pins a thread at 100% CPU with no allocation. This is reachable with a single message. `JsonRpcServer` and `JsonRpcClient` fall back to `DefaultJsonRpcMapper` whenever no mapper is passed (`JsonRpcServer.java:84` and `:114`, `JsonRpcClient.java:186`), and that mapper hands the raw message body straight to `JSONReader.read()` (`DefaultJsonRpcMapper.java:42` for the server request, `:52` for the client reply). A caller that can publish to the RPC request queue hangs the server; a malicious or MITM'd JSON-RPC service does the same to a client. ## Proof of concept Against `amqp-client` 5.36.0 from Maven Central:
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-cqgh-8p3p-mx4m
Open original source · Updated Oct 07, 2026
RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | com.rabbitmq:amqp-client | 5.36.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:42:33-04:00
MODIFIED 2026-10-07T16:42:34-04:00
INGESTED 2026-10-08T12:30:44-04:00