Inefficient regular expression complexity in RabbitMQ Server - #VU137231
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the AMQP 1.0 SQL filter LIKE handling when evaluating crafted LIKE filters against delivered messages. A remote user can attach a receiver with a crafted filter and publish messages with long property values to cause a denial of service.
Exploitation requires AMQP 1.0 with stream queues in use.