Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-57212

RabbitMQ management HTTP API accepts request bodies larger than the configured limit

Technology

RabbitMQ

CVSS Score

7.7 / 10.0

Affected Versions

3.13.0 to 3.13.13; 4.0.0 to 4.0.18; 4.1.0 to 4.1.9; 4.2.0 to 4.2.4

Upstream Fix

4.2.5 (public); 3.13.14, 4.0.19, 4.1.10 (commercial)

Published

July 10, 2026

OSSeva Coverage

Fixed upstream

Description

The management plugin's read_complete_body checked the accumulated size before the final chunk but not the final combined size, so the HTTP API accepted oversized but valid JSON bodies on its decode and direct request paths, beyond the configured maximum. Fixed in 4.2.5 and in the commercial 3.13.14, 4.0.19 and 4.1.10.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.13; 4.0.0 to 4.0.18; 4.1.0 to 4.1.9; 4.2.0 to 4.2.4, you need this patch. Book a discovery call to get covered.