PT-2026-97585 · Vmware · Rabbitmq

CVE-2026-67235

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.3.0 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 3.13.15
Description An authenticated AMQP 0-9-1 client with publish permissions can cause a denial of service. The issue occurs because the BodySize in the content-header is stored without validation against max message size, and the size check only executes upon assembly completion. By setting body size to 2^63-1 and streaming fragments, a client can bypass the check msg size function, leading to unbounded memory accumulation in the reader process. This can result in the node running out of memory or triggering a memory alarm that degrades all publishers across the cluster.
Recommendations Update to version 4.3.0 Update to version 4.2.6 Update to version 4.1.11 Update to version 4.0.20 Update to version 3.13.15

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67235
GHSA-Q8G2-PC7M-M3JW

Affected Products

Rabbitmq