CVE-2026-57212: Broadcom Rabbitmq Server
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
Affected products
- Broadcom Rabbitmq Server: from 3.13.0, before 4.2.5 (fixed in 4.2.5)
Published 2026-07-10. Last modified 2026-07-13.