Resource exhaustion in RabbitMQ Server - #VU143934
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the rabbitmq_web_stomp STOMP parser when processing compressed pre-authentication WebSocket STOMP messages. A remote attacker can send many highly compressible incomplete STOMP messages with a large declared content-length to cause a denial of service.
Exploitation requires the Web STOMP plugin to be enabled, a reachable Web STOMP listener, and negotiated permessage-deflate compression.