PT-2026-97585 · Vmware · Rabbitmq
CVE-2026-67235
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.3.0
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 3.13.15
Description
An authenticated AMQP 0-9-1 client with publish permissions can cause a denial of service. The issue occurs because the
BodySize in the content-header is stored without validation against max message size, and the size check only executes upon assembly completion. By setting body size to 2^63-1 and streaming fragments, a client can bypass the check msg size function, leading to unbounded memory accumulation in the reader process. This can result in the node running out of memory or triggering a memory alarm that degrades all publishers across the cluster.Recommendations
Update to version 4.3.0
Update to version 4.2.6
Update to version 4.1.11
Update to version 4.0.20
Update to version 3.13.15
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq