THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5xwg-cfvj-gff5 (low) — RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

[GHSA] GHSA-5xwg-cfvj-gff5 (low) — RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

medgithub_advisoriesPublished 2026-08-18

GHSA-5xwg-cfvj-gff5 Severity: low CVE: CVE-2026-61634

RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max

## Summary The max body size was enforced to patch CVE-2023-46120, but even though that limit still works, the frame size itself still exceeds the given max size.

## Root cause The Java client records the AMQP 0-9-1 `frame_max` negotiated during connection

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5xwg-cfvj-gff5