Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-57220

RabbitMQ stream listener ignores its frame size limit before authentication

Technology

RabbitMQ

CVSS Score

7.5 / 10.0

Affected Versions

4.2.0 to 4.2.5

Upstream Fix

4.2.6

Published

July 10, 2026

OSSeva Coverage

Fixed upstream

Description

The stream listener did not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, so an unauthenticated remote client could declare oversized frame lengths and consume broker memory. Fixed in 4.2.6. NVD has not scored the record; the score is GitHub's as the CNA.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.