Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-57220
RabbitMQ stream listener ignores its frame size limit before authentication
Technology
RabbitMQ
CVSS Score
7.5 / 10.0
Affected Versions
4.2.0 to 4.2.5
Upstream Fix
4.2.6
Published
July 10, 2026
OSSeva Coverage
Fixed upstream
Description
The stream listener did not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, so an unauthenticated remote client could declare oversized frame lengths and consume broker memory. Fixed in 4.2.6. NVD has not scored the record; the score is GitHub's as the CNA.
Is your RabbitMQ deployment affected?
If you're running 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.