Resource exhaustion in RabbitMQ Server - #VU137243
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in auth_mechanism URI token processing in amqp_client when handling auth_mechanism query values. A remote privileged user can send a specially crafted request with a large number of colon-separated tokens to cause a denial of service.
Exploitation requires the Shovel or Federation plugin to be in use.