Resource exhaustion in RabbitMQ Server - #VU137238
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in lookup_component/1 in rabbit_runtime_parameters.erl when processing the :component segment of runtime-parameter request URLs. A remote privileged user can send roughly one million requests with distinct component values to cause a denial of service.
Exploitation requires policymaker privileges.