Listen to this Post
The vulnerability stems from how the `com.rabbitmq.tools.json.JSONReader.read()` method processes input strings and comments.
When a JSON payload ends abruptly inside a quoted string or a double-slash line comment, the internal parsers fail to exit correctly.
Both the string scanner and the whitespace scanner utilize `StringCharacterIterator.next()` to traverse the incoming character stream.
However, these scanners only check for specific closing delimiters such as a matching quote or a newline character to terminate their loops.
Once the iterator reaches the end of the input stream, it returns CharacterIterator.DONE, which is represented by the unicode replacement character.
Because the scanners do not check for this termination sentinel value, they loop forever consuming resources.
In the string scanning logic (string()), the parser continuously appends the sentinel character to an internal `StringBuilder` on every single iteration.
This uncontrolled growth rapidly exhausts the available heap memory allocated to the Java Virtual Machine.
Consequently, the application throws an OutOfMemoryError, crashing the entire JVM process instantly.
Meanwhile, the comment scanning logic (skipWhiteSpace()) runs an infinite loop searching for a newline character that never arrives.
This pins the CPU core executing the thread at 100% utilization with zero memory allocation, leading to persistent thread starvation.
These parsers are invoked automatically by the default `DefaultJsonRpcMapper` class whenever no custom mapper is explicitly provided.
Both `JsonRpcServer` and `JsonRpcClient` components rely on this default mapper to process incoming RPC message bodies and replies.
An unauthenticated attacker who can publish a maliciously crafted message with an unterminated string to the RPC request queue can crash the server.
Similarly, a malicious or man-in-the-middle controlled JSON-RPC service can send a truncated response payload to hang client applications.
Because the server-side `doCall` method only catches explicit `ClassCastException` errors, heap exhaustion or thread pinning cannot be caught per request.
This results in a complete, unrecoverable denial of service vector affecting the entire running process from a single remote message.
DailyCVE Form:
Platform: RabbitMQ Java Client
Version: Prior to 5.37.0
Vulnerability: Denial of Service
Severity: Medium severity
date: October 2026
Prediction: October 1 2026
What Undercode Say:
Analytics show that legacy JSON-RPC-over-AMQP components in Java clients contain unmaintained parsing logic vulnerable to resource exhaustion.
Bash commands for compilation and testing:
javac -cp amqp-client-5.36.0.jar Poc.java java -Xmx64m -cp amqp-client-5.36.0.jar:. Poc
Exploit: (Educational Purposes!)
import com.rabbitmq.tools.jsonrpc.DefaultJsonRpcMapper;
public class Poc {
public static void main(String[] args) {
DefaultJsonRpcMapper mapper = new DefaultJsonRpcMapper();
mapper.parse("{\"method\":\"x", String.class); // unterminated string
// mapper.parse("//", String.class); // unterminated // comment
System.out.println("unreachable");
}
}
Protection: from this CVE
Upgrade the RabbitMQ Java client library to version 5.37.0 or higher where the input scanners correctly terminate at CharacterIterator.DONE. Alternatively, avoid using the deprecated JSON-RPC components and switch to modern mappers such as JacksonJsonRpcMapper.
Impact:
A single small, unauthenticated message can completely halt a JSON-RPC endpoint. An unterminated string triggers an `OutOfMemoryError` that brings down the entire JVM process, while an unterminated comment locks up a worker thread at 100% CPU utilization indefinitely, causing unrecoverable service downtime.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

