CVE-2026-67235: Rabbitmq Rabbitmq-Server
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assembly completed. By declaring body_size = 2^63-1 and then streaming fragments, a client ensured that check_msg_size never fired, so the accumulated body size went unbounded. A reader process accumulates memory until the memory alarm fires, degrading all publishers cluster-wide, or until the node runs out of memory. The memory alarm provides only partial mitigation, since it is reactive rather than preventive. AMQP 0-9-1 is the most widely used protocol, and any publisher can trigger this condition. Preconditions include Any authenticated AMQP 0-9-1 client with publish permission can exploit this.. This issue is fixed in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.
Affected products
- Rabbitmq Rabbitmq-Server: from 4.2.0, before 4.2.6 (fixed in 4.2.6); from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.0.0, before 4.0.20 (fixed in 4.0.20); from 3.13.0, before 3.13.15 (fixed in 3.13.15)
Published 2026-09-23. Last modified 2026-09-24.