PT-2026-57305 · Vmware+1 · Rabbitmq

CVE-2026-57220

·

Published

2026-07-10

·

Updated

2026-07-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.2.6
Description The RabbitMQ stream listener fails to enforce the configured stream frame-size limit when assembling frames during authentication and before Tune negotiation. This allows an unauthenticated remote client to declare oversized frame lengths, leading to excessive memory consumption within rabbit stream core and potentially causing a Denial of Service (DoS), which is a condition where the service becomes unavailable to legitimate users.
Recommendations Update to version 4.2.6.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92337
CVE-2026-57220
GHSA-F364-87Q5-J35Q
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq