PT-2026-97559 · Vmware · Rabbitmq

CVE-2026-66072

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.1
Description An authenticated stream client with read access to any stream can crash the broker node. This occurs because the get chunk selector/1 function calls binary to atom on the raw client-supplied chunk selector property from post-auth subscribe and resolve offset spec frames without a whitelist or existing guard. This issue requires the rabbitmq stream plugin to be enabled and an authenticated stream-protocol user with read access to at least one stream.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.1.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66072
GHSA-48HM-CHGV-398R

Affected Products

Rabbitmq