Improper handling of highly compressed data in RabbitMQ Server - #VU137251
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the rabbit_web_mqtt_handler WebSocket handling path when processing a highly compressed WebSocket frame with permessage-deflate enabled. A remote attacker can send a specially crafted compressed WebSocket frame to cause a denial of service.
Only systems with the rabbitmq_web_mqtt plugin enabled are vulnerable.