CVE-2026-69219
Last modified
CVE-2026-69219 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before checking the bytes available in the frame. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below Integer.MAX_VALUE and allocate a byte array before checking the bytes available in the frame. A malicious AMQP peer can send a LongString or byte-array field with type tag S and a declared length such as 0x7FFFFFFE during the pre-authentication connection.start server-properties table, causing an approximately 2 GB allocation and OutOfMemoryError before readFully consumes data. The resulting memory exhaustion can terminate the JVM and cause denial of service. This issue is fixed in version 5.33.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rabbitmq | rabbitmq-java-client | < 5.33.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-69219?
How severe is CVE-2026-69219?
How do I fix CVE-2026-69219?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69213Http4s is a Scala interface for HTTP services. Prior to 0.23…7.5
- CVE-2026-69214Http4s is a Scala interface for HTTP services. Prior to 0.23…6.8
- CVE-2026-69215Http4s is a Scala interface for HTTP services. Prior to 0.23…6.8
- CVE-2026-69216Http4s is a Scala interface for HTTP services. Prior to 0.23…5.4
- CVE-2026-69217Http4s is a Scala interface for HTTP services. Prior to 0.23…8.7
- CVE-2026-69218Http4s is a Scala interface for HTTP services. Prior to 0.23…7.5
- CVE-2026-6922The WP Table Builder – Drag & Drop Table Builder plugin for …7.1
- CVE-2026-69220The RabbitMQ Java client library allows Java and JVM-based a…8.7
- CVE-2026-69222LiquidJS is a Shopify / GitHub Pages compatible template eng…7.5
- CVE-2026-69223Apache Allura's webhooks are vulnerable to Server-Side Reque…9.1
- CVE-2026-69224There is an information disclosure vulnerability in Esri Por…7.5
- CVE-2026-69225There is an information disclosure vulnerability in Esri Por…7.5
Are you affected by CVE-2026-69219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
