Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137246

 

Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137246

Published: July 9, 2026


Vulnerability identifier: #VU137246
CSH Severity: Low
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the consistent-hash exchange binding handling when processing a queue binding request with an excessively large routing-key weight. A remote user can create a binding with an arbitrarily large integer weight to cause a denial of service.

Only instances with the rabbitmq_consistent_hash_exchange plugin enabled are vulnerable, and the oversized allocation is replicated across cluster nodes and persists across restarts.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6

External References

Related Security Bulletins