Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137252

 

Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137252

Published: July 9, 2026


Vulnerability identifier: #VU137252
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the amqp10_binary_parser array32 parser when parsing a crafted pre-authentication AMQP 1.0 SASL-init frame. A remote attacker can send a specially crafted frame to cause a denial of service.

Only nodes with the AMQP 1.0 listener enabled are vulnerable, and all tenants and protocols on the affected node lose service when the Erlang VM terminates.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6

External References

Related Security Bulletins