Allocation of Resources Without Limits or Throttling in RabbitMQ Server - #VU139303
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the AMQP 1.0 type parser when parsing a crafted AMQP 1.0 frame containing many zero-width arrays. A remote user can send a specially crafted frame after completing a SASL handshake to cause a denial of service.
The issue is triggered in the connection reader before validation or authorization of the parsed frame body, and user interaction is not required.