PT-2026-98909 · Rabbitmq+1 · Rabbitmq Web Stomp+1
CVE-2026-67230
·
Published
2026-09-25
·
Updated
2026-09-29
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 3.13.0 through 3.13.14
RabbitMQ versions 4.0.x prior to 4.0.20
RabbitMQ versions 4.1.x prior to 4.1.11
RabbitMQ versions 4.2.x prior to 4.2.6
Description
The Web STOMP WebSocket handler fails to enforce
max frame size and login timeout before authentication. This allows an unauthenticated client to maintain a connection using a slow stream of small frames, leading to the accumulation of unbounded pre-authentication state. This issue requires the rabbitmq web stomp plugin to be enabled.Recommendations
Update to version 3.13.15.
Update to version 4.0.20.
Update to version 4.1.11.
Update to version 4.2.6.
As a temporary mitigation, disable the
rabbitmq web stomp plugin.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq
Rabbitmq Web Stomp