Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137249
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the WebSocket path in the Web-STOMP handler when processing pre-authentication STOMP frames over WebSocket connections. A remote attacker can send a slow trickle of single-byte frames to cause a denial of service.
The rabbitmq_web_stomp plugin must be enabled.