Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137248
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in validate_partitions when processing partition count values in super-stream partition requests. A remote privileged user can submit a request with an excessively large partition count to cause a denial of service.
The rabbitmq_stream_management plugin must be enabled, and exploitation requires access to the target vhost.