CVE-2026-61634
ADVISORY - githubSummary
Summary
The max body size was enforced to patch CVE-2023-46120, but even though that limit still works, the frame size itself still exceeds the given max size.
Root cause
The Java client records the AMQP 0-9-1 frame_max negotiated during connection tuning, but the socket inbound frame reader continues to validate broker-controlled payload lengths against the much larger maxInboundMessageBodySize limit. A broker peer can therefore send a method frame whose payload is larger than the negotiated frame_max, have it allocated and decoded, and complete the connection handshake instead of being rejected as a protocol violation.
Reported by Team Atlanta.
NIST
-
GitHub
-
CVSS SCORE
N/AlowDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumChainguard
CGA-8rr9-62hv-h636
-
minimos
MINI-599w-36v5-45p5
-
minimos
MINI-fh8r-cgh7-wxc5
-
minimos
MINI-jg3x-88g9-mv6m
-
minimos
MINI-jq9f-6v46-hfqh
-
minimos
MINI-m59m-2v58-55x2
-
minimos
MINI-q4fc-2mxp-75p4
-
minimos
MINI-qqf8-fv9x-vpv2
-
minimos
MINI-v4j4-m9g2-rmxj
-
minimos
MINI-w7wg-w358-m35p
-