Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137246
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the consistent-hash exchange binding handling when processing a queue binding request with an excessively large routing-key weight. A remote user can create a binding with an arbitrarily large integer weight to cause a denial of service.
Only instances with the rabbitmq_consistent_hash_exchange plugin enabled are vulnerable, and the oversized allocation is replicated across cluster nodes and persists across restarts.