Resource exhaustion in RabbitMQ Server - #VU139297
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the rabbitmq_management global parameter endpoint when handling repeated requests to /api/global-parameters/:name with unique name values. A remote privileged user can send repeated crafted requests with unique path values to cause a denial of service.
The management plugin must be enabled, and exploitation requires approximately one million HTTP requests.