CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-106121

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·6 min read·6 visits

Executive Summary (TL;DR)

A Denial of Service vulnerability in RabbitMQ Java Client's legacy JSON reader permits authenticated attackers to trigger 100% CPU exhaustion or JVM OutOfMemoryError crashes by sending malformed or truncated JSON payloads.

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Vulnerability Overview and Context

CVE-2026-106121 identifies a high-impact Denial of Service (DoS) vulnerability in the amqp-client artifact of the RabbitMQ Java Client. The flaw resides within the custom JSON deserialization class com.rabbitmq.tools.json.JSONReader. This component parses JSON-RPC message payloads sent to network interfaces processing RPC actions and client replies.

The parsing engine exposed by the client library relies on standard internal traversal logic to translate string-based serialized formats into JVM objects. Under default configurations, applications executing JsonRpcServer and JsonRpcClient utilize DefaultJsonRpcMapper, which internally registers JSONReader to map incoming requests. An attacker targeting this interface can submit malformed payloads that force the underlying parsing scanner into infinite loop loops.

This flaw belongs to the class of CWE-835 (Loop with Unreachable Exit Condition). Because the parser operates directly on incoming network sockets or input streams, exploitation bypasses standard application layer validation rules. The vulnerability represents an unauthenticated, remote vectors-of-attack vector, provided that the application exposes JSON-RPC endpoints to the network.

Root Cause Analysis of the Loop Exit Flaw

To understand the technical root cause of CVE-2026-106121, it is necessary to examine how JSONReader interacts with Java's standard java.text.StringCharacterIterator. This class maintains an internal pointer to traverse input strings character-by-character. When the iterator reaches the end of the input stream, subsequent invocations of next() perpetually return the constant sentinel value CharacterIterator.DONE (represented by \uFFFF).

The unpatched parser implementation fails to check for this sentinel value during loop operations within two primary parsing methods: skipWhiteSpace() and string(). Specifically, skipWhiteSpace() implements logic to handle inline single-line JavaScript-style comments starting with //. When processing a comment block, the code loops until it detects a line break (\n) character. If the payload ends abruptly with a comment that lacks a newline, the iterator reaches the end, returning \uFFFF. Since \uFFFF is never equal to \n, the scanner falls into an infinite loop that consumes 100% of the executing thread's CPU cycles.

A more destructive variant occurs inside the string() method, which deserializes quoted string literals. The loop continues to iterate and read characters until it encounters the matching closing delimiter. In a truncated payload (for example, {"method":"x), the closing quotation mark is never reached. The parser enters an infinite loop, reading the CharacterIterator.DONE sentinel (\uFFFF) and continually appending it to an internal StringBuilder instance. This leads to rapid heap memory consumption, ending in an unavoidable OutOfMemoryError that terminates the JVM process.

Source Code Differential Analysis

The vulnerability was mitigated in commit 25fad817291feff3195c32620117d295598f8b41 by incorporating explicit boundary checks against the CharacterIterator.DONE sentinel value. Let us examine the vulnerable block in JSONReader.java compared to the patched logic.

Prior to the patch, the loop in skipWhiteSpace scanned comments without verifying stream completion:

// Vulnerable comment scanning loop
else if (c == '/' && next() == '/') {
    while (c != '\n') {
        next();
    }
}

The updated implementation introduces a compound termination check that halts execution upon encountering the end-of-input sentinel:

// Patched comment scanning loop
else if (c == '/' && next() == '/') {
    while (c != '\n' && c != CharacterIterator.DONE) {
        next();
    }
}

Similarly, the string() method was hardened to detect stream exhaustion, throwing an explicit exception rather than executing indefinitely:

// Patched string parsing logic
private Object string(char sep) {
    buf.setLength(0);
    while (c != sep) {
        if (c == CharacterIterator.DONE) {
            throw new IllegalStateException(
                "Unterminated string while parsing JSON (around character "
                    + (it.getIndex() - it.getBeginIndex()) + ")");
        }
        if (c == '\\') {
            next();
            if (c == 'u') {
                // Unicode parsing logic...
            }
        }
        buf.append(c);
        next();
    }
}

Furthermore, the patch implements structural changes to JsonRpcServer.java to handle any unexpected runtime exceptions. Previously, the handler only intercepted ClassCastException occurrences, allowing other runtime errors to crash execution threads. The updated server wraps parsing and dispatch routines in a broad RuntimeException catch block, logging the error and returning an HTTP 400 Bad Request response to ensure server availability.

Exploitation and Attack Vectors

Exploitation of CVE-2026-106121 requires network access to endpoints implementing JsonRpcServer running on top of vulnerable versions of the RabbitMQ Java Client. An attacker must construct and transmit specialized, malformed JSON structures that trigger either the comment parsing loop or the string allocation loop.

To execute a Thread Exhaustion Attack (100% CPU usage), the attacker sends a payload terminated with a single-line comment. This can be accomplished with a minimal body such as {"method":"test"}//. Because the parsing thread cannot break out of the loop in skipWhiteSpace(), the host thread remains permanently active. If the attacker submits multiple identical requests, they can exhaust the server's thread pool, rendering the application unresponsive to legitimate users.

To execute a Heap Exhaustion Attack, the attacker transmits an unclosed string delimiter, such as " or ["x. The parsing thread enters the string() parser loop and allocates heap memory continuously by appending \uFFFF to the StringBuilder object. Because Java string builders double their capacity during resizing, this triggers exponential memory allocation, quickly overwhelming the JVM's maximum heap capacity (-Xmx). This results in a fatal java.lang.OutOfMemoryError crash that terminates the entire application server process.

Remediation and Secure Configurations

The primary remediation for CVE-2026-106121 is updating the RabbitMQ Java Client (amqp-client) library to version 5.37.0 or higher. This version implements robust boundary checking inside the custom parser and protects the runtime thread of JsonRpcServer against unexpected parsing exceptions.

Because the custom JSON parsing framework in the com.rabbitmq.tools.json package is legacy and deprecated, development teams should transition away from it entirely. Replacing DefaultJsonRpcMapper with JacksonJsonRpcMapper mitigates the flaw by leveraging the Jackson parsing engine, which does not suffer from these parsing loop weaknesses. This migration represents a long-term architectural solution that increases both security and processing performance.

In environments where immediate software upgrades are not viable, administrators should configure upstream Web Application Firewalls (WAF) or ingress gateways to validate incoming JSON structures. Specifically, rules should reject incoming HTTP POST requests with malformed JSON-RPC payloads, trailing comments (such as those starting with //), or unmatched quotation marks. Implementing these filters blocks the malicious payloads before they are processed by the vulnerable JVM application threads.

Fix Analysis (1)

Technical Appendix

CVSS Score
4.9/ 10
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS Probability
0.49%
Top 60% most exploited

Affected Systems

JVM applications using the legacy JSON-RPC server mapper (DefaultJsonRpcMapper) in RabbitMQ Java ClientRabbitMQ Java Client (com.rabbitmq:amqp-client)

Affected Versions Detail

Product
Affected Versions
Fixed Version
amqp-client
RabbitMQ
>= 5.19.0, < 5.37.05.37.0
AttributeDetail
CWE IDCWE-835
Attack VectorNetwork
CVSS v3.1 Score4.9 (Medium)
EPSS Score0.00493 (Percentile: 40.36%)
ImpactDenial of Service (CPU Starvation / JVM Crash)
Exploit StatusProof-of-Concept Available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1499.004Endpoint Denial of Service: Application Exhaustion Flood
Impact
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')

The program contains an iteration loop with an exit condition that cannot be reached or is never met, leading to an infinite loop.

Known Exploits & Detection

GitHub Security AdvisoryExploit concepts details including malformed payloads trigger CPU starvation and JVM OutOfMemory crashes.

References & Sources

  • [1]CVE-2026-106121 CVE Record
  • [2]NVD CVE-2026-106121
  • [3]GitHub Security Advisory GHSA-cqgh-8p3p-mx4m
  • [4]Official Fix Commit 25fad817
  • [5]Hardening Pull Request #2100
  • [6]RabbitMQ Java Client v5.37.0 Release Tag

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•42 minutes ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
1 views•6 min read
•about 2 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
4 views•6 min read
•about 5 hours ago•CVE-2026-105646
4.9

CVE-2026-105646: Regular Expression Denial of Service in Ghost CMS Import Handlers

An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.

Alon Barad
Alon Barad
8 views•6 min read
•about 6 hours ago•CVE-2026-105645
4.9

CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.

Amit Schendel
Amit Schendel
8 views•6 min read
•about 7 hours ago•CVE-2026-105644
6.8

CVE-2026-105644: Stored Cross-Site Scripting via Malicious SVG Content Import in Ghost CMS

A Stored Cross-Site Scripting (XSS) and Unrestricted Upload of File with Dangerous Type vulnerability in Ghost CMS (versions 4.0.0 to 6.66.x) allows remote attackers to execute arbitrary JavaScript in the context of an administrator's session. The flaw lies in the content import subsystem, which extracted and stored SVG files without sanitization or binary verification.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 8 hours ago•CVE-2026-105643
7.3

CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.

Alon Barad
Alon Barad
9 views•6 min read