Missing Authorization in RabbitMQ Server - #VU137255
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the /federation-links/.../restart route when handling DELETE requests to restart federation links. A remote user can send a specially crafted DELETE request with monitoring-tag credentials to cause a denial of service.
Exploitation requires the rabbitmq_federation and rabbitmq_federation_management plugins to be enabled.