PT-2026-97584 · Vmware+1 · Rabbitmq+1

CVE-2026-67232

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An unauthenticated attacker can crash a node running the Web-MQTT plugin by sending a single highly-compressed WebSocket frame that inflates to gigabytes in memory. This occurs because the cowboy WebSocket options enable RFC 7692 permessage-deflate negotiation without setting a max frame size, causing the default value of infinity to apply. The cow ws:parse payload/9 function calls zlib:inflate/2 on the compressed payload without an output-size limit, allowing a zlib bomb to be processed. Decompression happens during the connection process before the websocket handle/2 function processes the MQTT bytes, meaning no credentials are required. This requires the rabbitmq web mqtt plugin to be enabled and network reachability to ports 15675 or 15676.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.0. As a temporary mitigation, disable the rabbitmq web mqtt plugin or restrict network access to ports 15675 and 15676.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67232
GHSA-GMGX-HHG5-43GR

Affected Products

Rabbitmq
Rabbitmq Web Mqtt