PT-2026-97575 · Vmware · Rabbitmq

CVE-2026-66074

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An issue exists where the match value/3 function passes a user-supplied regular expression via the ?name= parameter to re:run without a match limit option. This regular expression is executed once for every resource in the result set. When processing large sets, such as 5000 queues, a single request can consume excessive CPU time, and parallel requests can saturate the schedulers. This path is accessible through normal API use via the use regex=true option on list endpoints. Any user with the management tag can exploit this behavior.
Recommendations Update to version 3.13.15 Update to version 4.0.20 Update to version 4.1.11 Update to version 4.2.6 Update to version 4.3.0

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66074
GHSA-RG5Q-VCGF-RFH7

Affected Products

Rabbitmq