GHSA-6g32-pxv4-2wfj
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
Quick fix
GHSA-6g32-pxv4-2wfj — com.rabbitmq:amqp-client: upgrade to the fixed version with the command below.
# pom.xml: bump <version>5.33.0</version> for com.rabbitmq:amqp-client Details
The JSON-RPC tools in `com.rabbitmq.tools.jsonrpc` perform `Class.forName(javaReturnType)` with `initialize=true` on class names received from untrusted AMQP messages, without any validation or allowlist.
**Vulnerable code** (`ProcedureDescription.java:101-127`): When a `JsonRpcClient` connects, it calls `system.describe` and receives a service description from the AMQP queue. The response JSON includes `javaReturnType` fields that are reflectively set via `JSONUtil.tryFill()`, triggering `setJavaReturnType()` → `computeReturnTypeAsJavaClass()` → `Class.forName(javaReturnType)`.
**Attack scenario:** 1. Victim uses `JsonRpcClient` to connect to a JSON-RPC service via RabbitMQ 2. Attacker (co-tenant on shared broker, or MITM) intercepts the `system.describe` request 3. Attacker responds with crafted `javaReturnType` values 4. Victim's client calls `Class.forName(attackerInput)` with default `initialize=true` 5. Static initializers of attacker-specified classes execute in victim's JVM
Additionally, the loaded class from `getReturnType()` is passed to `mapper.parse(replyStr, expectedType)` at `JsonRpcClient.java:168`, potentially enabling type-confusion.
**Recommended fix:** Use `Class.forName(javaReturnType, false, classLoader)` to prevent static initializer execution, or add an allowlist of permitted return types.
**CWE:** CWE-470
---
**Reply from reporter (2026-06-29):** Thanks for the quick turnaround. Fix looks good. Looking forward to the CVE assignment.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 5.33.0 # pom.xml: bump <version>5.33.0</version> for com.rabbitmq:amqp-client References
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj [WEB]
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2000 [WEB]
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2002 [WEB]
- https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb [WEB]
- https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 [WEB]
- https://github.com/rabbitmq/rabbitmq-java-client [PACKAGE]
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0 [WEB]