Resource exhaustion in RabbitMQ Server - #VU137237
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in vhost metadata import handling when importing a crafted definitions file via the definitions API. A remote privileged user can submit a definitions import request containing a large number of unique metadata keys to cause a denial of service.
The issue is triggered during processing of vhost metadata keys with atomize_keys/1.