CVE-2026-66080: Rabbitmq Rabbitmq-Server

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000) allocates roughly 8GB. Preconditions include The rabbitmq_stream_management plugin must be enabled. The caller needs the management tag and access to the target vhost.. This issue is fixed in versions 4.1.11, 4.2.6, and 4.3.0.

Affected products

  • Rabbitmq Rabbitmq-Server: from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.6 (fixed in 4.2.6)

Published 2026-09-23. Last modified 2026-09-24.