PT-2026-98909 · Rabbitmq+1 · Rabbitmq Web Stomp+1

CVE-2026-67230

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.14 RabbitMQ versions 4.0.x prior to 4.0.20 RabbitMQ versions 4.1.x prior to 4.1.11 RabbitMQ versions 4.2.x prior to 4.2.6
Description The Web STOMP WebSocket handler fails to enforce max frame size and login timeout before authentication. This allows an unauthenticated client to maintain a connection using a slow stream of small frames, leading to the accumulation of unbounded pre-authentication state. This issue requires the rabbitmq web stomp plugin to be enabled.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. As a temporary mitigation, disable the rabbitmq web stomp plugin.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67230
GHSA-7V63-J4GM-P4RH

Affected Products

Rabbitmq
Rabbitmq Web Stomp