PT-2026-98924 · Vmware · Rabbitmq
CVE-2026-67419
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.3.5
Description
An authenticated user with permissions to bind a queue to a topic exchange and publish to it can cause a denial of service. By using consecutive # segments in a binding key, the user can force topic matchers to revisit the same trie-node and routing-key-suffix states without memoization. This process materializes duplicate destinations before deduplication, leading to combinatorial CPU consumption and memory pressure that can disrupt routing services for all tenants.
Recommendations
Update to version 4.3.5.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rabbitmq