THREAT OPS › Threat News › [GHSA] GHSA-5xwg-cfvj-gff5 (low) — RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
[GHSA] GHSA-5xwg-cfvj-gff5 (low) — RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
GHSA-5xwg-cfvj-gff5 Severity: low CVE: CVE-2026-61634
RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max
## Summary The max body size was enforced to patch CVE-2023-46120, but even though that limit still works, the frame size itself still exceeds the given max size.
## Root cause The Java client records the AMQP 0-9-1 `frame_max` negotiated during connection
Indicators of compromise
- CVE-2026-61634cve
- CVE-2023-46120cve
Original source: https://github.com/advisories/GHSA-5xwg-cfvj-gff5