Inefficient Algorithmic Complexity in RabbitMQ Server - #VU143936
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in direct reply-to address resolution and volatile target handling when processing forged direct reply-to routing keys in the AMQP CC header. A remote user can send a specially crafted AMQP message with many distinct forged suffixes to cause a denial of service.
Exploitation requires an authenticated AMQP account with permission to write to the default exchange and activation of direct reply-to to obtain a generated reply address.