Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137239
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in rabbit_stream_core when processing inbound stream-protocol frames before authentication. A remote attacker can send a frame with a declared size exceeding the negotiated frame_max to cause a denial of service.
The stream plugin must be enabled.