Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137252
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the amqp10_binary_parser array32 parser when parsing a crafted pre-authentication AMQP 1.0 SASL-init frame. A remote attacker can send a specially crafted frame to cause a denial of service.
Only nodes with the AMQP 1.0 listener enabled are vulnerable, and all tenants and protocols on the affected node lose service when the Erlang VM terminates.