PT-2026-97562 · Vmware · Rabbitmq

CVE-2026-66079

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description An unauthenticated network attacker can crash a RabbitMQ node with the AMQP 1.0 listener enabled by sending a single ~19-byte frame. The issue occurs because the parse array primitive/2 function for constructor 0x45 (list0) returns a byte-width of 0. The array32 parser reads a 4-byte Count from the wire and loops Count times; when the width is 0, no input is consumed, allowing a payload with Count set to 0xFFFFFFFF to be accepted. This causes the reader process, which uses the amqp10 framing:decode bin/1 function in rabbit amqp reader.erl:412 to parse SASL-mechanisms or SASL-init frames before authentication, to attempt to build a list of approximately 4 billion empty elements. This exhausts heap memory and terminates the Erlang VM, resulting in a loss of service for all tenants and protocols on the node.
Recommendations Update to version 3.13.15 or later. Update to version 4.0.20 or later. Update to version 4.1.11 or later. Update to version 4.2.6 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66079
GHSA-C66H-HF5J-8JF9

Affected Products

Rabbitmq