Resource exhaustion in RabbitMQ Server - #VU137290
Published: July 10, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the rabbitmq stream reader when processing client-supplied chunk_selector properties in post-auth subscribe and resolve_offset_spec frames. A remote user can repeatedly send crafted stream protocol frames with fresh chunk_selector values to cause a denial of service.
Only instances with the rabbitmq_stream plugin enabled are vulnerable.