PT-2026-98922 · Rabbitmq+1 · Rabbitmq Jms Topic Exchange+1
CVE-2026-67413
·
Published
2026-09-20
·
Updated
2026-10-01
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.0.0 through 4.0.22
RabbitMQ versions 4.1.0 through 4.1.13
RabbitMQ versions 4.2.0 through 4.2.8
RabbitMQ versions 4.3.0 through 4.3.2
Description
The optional
rabbitmq jms topic exchange plugin's x-jms-topic exchange accepts a client-controlled rjms erlang selector binding expression. The LIKE evaluator in this process expands percent and underscore wildcards into overlapping PCRE (Perl Compatible Regular Expressions) fragments. These fragments are executed using the re:run/3 function without match or recursion limits. Consequently, an authenticated tenant with permissions to bind and publish can use pathological selectors to consume broker scheduler CPU, resulting in a denial of service.Recommendations
Update to version 4.0.23
Update to version 4.1.14
Update to version 4.2.9
Update to version 4.3.3
As a temporary mitigation, restrict the use of the
rabbitmq jms topic exchange plugin.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq
Rabbitmq Jms Topic Exchange