PT-2026-97562 · Vmware · Rabbitmq
CVE-2026-66079
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
Description
An unauthenticated network attacker can crash a RabbitMQ node with the AMQP 1.0 listener enabled by sending a single ~19-byte frame. The issue occurs because the
parse array primitive/2 function for constructor 0x45 (list0) returns a byte-width of 0. The array32 parser reads a 4-byte Count from the wire and loops Count times; when the width is 0, no input is consumed, allowing a payload with Count set to 0xFFFFFFFF to be accepted. This causes the reader process, which uses the amqp10 framing:decode bin/1 function in rabbit amqp reader.erl:412 to parse SASL-mechanisms or SASL-init frames before authentication, to attempt to build a list of approximately 4 billion empty elements. This exhausts heap memory and terminates the Erlang VM, resulting in a loss of service for all tenants and protocols on the node.Recommendations
Update to version 3.13.15 or later.
Update to version 4.0.20 or later.
Update to version 4.1.11 or later.
Update to version 4.2.6 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq