PT-2026-98924 · Vmware · Rabbitmq

CVE-2026-67419

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.3.5
Description An authenticated user with permissions to bind a queue to a topic exchange and publish to it can cause a denial of service. By using consecutive # segments in a binding key, the user can force topic matchers to revisit the same trie-node and routing-key-suffix states without memoization. This process materializes duplicate destinations before deduplication, leading to combinatorial CPU consumption and memory pressure that can disrupt routing services for all tenants.
Recommendations Update to version 4.3.5.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67419
GHSA-H964-V5MF-22CQ

Affected Products

Rabbitmq