PT-2026-97563 · Vmware+1 · Rabbitmq+1

CVE-2026-66080

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An issue exists in the validate partitions() function where it only verifies that the requested partition count is at least 1, without enforcing an upper limit. An attacker with the management tag and access to the target vhost can trigger excessive memory allocation (approximately 8GB) by providing a large count, such as lists:seq(0, 500000000). This requires the rabbitmq stream management plugin to be enabled.
Recommendations Update to version 4.1.11 Update to version 4.2.6 Update to version 4.3.0 As a temporary mitigation, disable the rabbitmq stream management plugin.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66080
GHSA-WG79-5449-M728

Affected Products

Rabbitmq
Rabbitmq Stream Management