Input validation error in RabbitMQ Server - CVE-2026-67418
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the MQTT 5 property parser and outbound PUBLISH property serializer when processing a crafted MQTT 5 PUBLISH packet containing an inapplicable property. A remote user can send a specially crafted PUBLISH message to cause a denial of service.
MQTT or Web MQTT must be enabled, and exploitation requires a separately authenticated MQTT 5 or Web MQTT subscriber on a matching topic or subscription filter.