Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU139303

 

Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU139303

Published: July 24, 2026


Vulnerability identifier: #VU139303
CSH Severity: Low
CVSS v4 BT: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the AMQP 1.0 type parser when parsing a crafted AMQP 1.0 frame containing many zero-width arrays. A remote user can send a specially crafted frame after completing a SASL handshake to cause a denial of service.

The issue is triggered in the connection reader before validation or authorization of the parsed frame body, and user interaction is not required.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 4.0.24, 4.1.15, 4.2.10, 4.3.4

External References

Related Security Bulletins