PT-2026-98906 · Vmware · Rabbitmq

CVE-2026-67225

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.14 RabbitMQ versions 4.0.x prior to 4.0.20 RabbitMQ versions 4.1.x prior to 4.1.11 RabbitMQ versions 4.2.x prior to 4.2.6
Description When the stream plugin is enabled, the stream protocol stores the FrameMax value negotiated during the Tune handshake but fails to compare it with the declared length of an inbound frame before buffering. This allows a remote client to trigger excessive memory pressure and a denial of service by declaring an oversized frame.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67225
GHSA-C8C4-GVV4-8J3Q

Affected Products

Rabbitmq