Resource exhaustion in RabbitMQ Server - #VU137245
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in rabbit_jms_topic_exchange.erl add_binding/3 when processing the rjms_erlang_selector binding argument on an x-jms-topic exchange. A remote user can send a specially crafted queue.bind request with arbitrary selector strings to cause a denial of service.
The rabbitmq_jms_topic_exchange plugin must be enabled, and exploitation can affect the entire broker node across tenants.