PT-2026-98922 · Rabbitmq+1 · Rabbitmq Jms Topic Exchange+1

CVE-2026-67413

·

Published

2026-09-20

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.0.0 through 4.0.22 RabbitMQ versions 4.1.0 through 4.1.13 RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description The optional rabbitmq jms topic exchange plugin's x-jms-topic exchange accepts a client-controlled rjms erlang selector binding expression. The LIKE evaluator in this process expands percent and underscore wildcards into overlapping PCRE (Perl Compatible Regular Expressions) fragments. These fragments are executed using the re:run/3 function without match or recursion limits. Consequently, an authenticated tenant with permissions to bind and publish can use pathological selectors to consume broker scheduler CPU, resulting in a denial of service.
Recommendations Update to version 4.0.23 Update to version 4.1.14 Update to version 4.2.9 Update to version 4.3.3 As a temporary mitigation, restrict the use of the rabbitmq jms topic exchange plugin.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105314
BIT-RABBITMQ-2026-67413
CVE-2026-67413
GHSA-CHXF-3HFG-J8F7
OESA-2026-3940
OESA-2026-4028
OESA-2026-4030
OESA-2026-4031
OESA-2026-4032

Affected Products

Rabbitmq
Rabbitmq Jms Topic Exchange