Resource exhaustion in RabbitMQ Server - #VU139300
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in rabbit_stream_super_stream_mgmt.erl when handling PUT requests to /api/stream/super-streams/{vhost}/{name} with a binding-keys field. A remote user can send a specially crafted request body to cause a denial of service.
Only instances with the rabbitmq_stream_management feature enabled are vulnerable, and reliable node termination was demonstrated in deployments running under a hard memory limit.