CVE-2026-57212
RabbitMQ management HTTP API accepts request bodies larger than the configured limit
Technology
RabbitMQ
CVSS Score
7.7 / 10.0
Affected Versions
3.13.0 to 3.13.13; 4.0.0 to 4.0.18; 4.1.0 to 4.1.9; 4.2.0 to 4.2.4
Upstream Fix
4.2.5 (public); 3.13.14, 4.0.19, 4.1.10 (commercial)
Published
July 10, 2026
OSSeva Coverage
Fixed upstream
Description
The management plugin's read_complete_body checked the accumulated size before the final chunk but not the final combined size, so the HTTP API accepted oversized but valid JSON bodies on its decode and direct request paths, beyond the configured maximum. Fixed in 4.2.5 and in the commercial 3.13.14, 4.0.19 and 4.1.10.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.13; 4.0.0 to 4.0.18; 4.1.0 to 4.1.9; 4.2.0 to 4.2.4, you need this patch. Book a discovery call to get covered.