Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU137258
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the AMQP 0-9-1 body assembly logic when processing published message body fragments after a crafted content-header declares an excessive BodySize. A remote user can send a specially crafted sequence of AMQP 0-9-1 publish frames to cause a denial of service.
Exploitation requires publish permission over AMQP 0-9-1.