CVE-2026-106121: RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, causing DoS
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.37.0, com.rabbitmq.tools.json.JSONReader.read() fails to terminate when input ends inside a quoted string or a line comment because its string and whitespace scanners do not stop at CharacterIterator.DONE. The default DefaultJsonRpcMapper passes JSON-RPC message bodies to this parser for JsonRpcServer and client replies. A truncated string causes the parser to append replacement end markers until heap exhaustion, while a line comment without a terminating newline can keep a thread consuming CPU indefinitely, resulting in denial of service. This issue is fixed in version 5.37.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RabbitMQ Java client libraryto a version that resolves this vulnerability.Fixed in 5.37.0
Event History
Frequently Asked Questions
Which applications are affected?
Applications using the RabbitMQ Java client before 5.37.0 are affected when they use the default DefaultJsonRpcMapper to process JSON-RPC requests with JsonRpcServer or JSON-RPC client replies.
What input is needed to trigger the denial of service?
An attacker needs to cause the JSON-RPC parser to receive truncated input. A quoted string that ends before its closing quote can exhaust heap memory, while a line comment that lacks a terminating newline can keep a thread consuming CPU indefinitely.
Is the default JSON-RPC configuration affected?
Yes. The vulnerable JSONReader is used by the default DefaultJsonRpcMapper for JSON-RPC server message bodies and client replies.
What is the available remediation?
Upgrade the RabbitMQ Java client to version 5.37.0, which fixes the parser termination issue.