Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2023-46118

RabbitMQ HTTP API has no request body limit, allowing memory exhaustion

Technology

RabbitMQ

CVSS Score

4.9 / 10.0

Affected Versions

3.11.0 to 3.11.23; 3.12.0 to 3.12.6 (NVD: all versions before 3.11.24)

Upstream Fix

3.11.24; 3.12.7

Published

October 25, 2023

OSSeva Coverage

Fixed upstream

Description

The HTTP API did not enforce a request body limit. An authenticated user with sufficient permissions could publish a very large message over the HTTP API and cause the node to be terminated by an out-of-memory mechanism. Fixed in 3.11.24 and 3.12.7.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.11.0 to 3.11.23; 3.12.0 to 3.12.6 (NVD: all versions before 3.11.24), you need this patch. Book a discovery call to get covered.