Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-66079

RabbitMQ AMQP 1.0 parser can be crashed before authentication with a 19-byte frame

Technology

RabbitMQ

CVSS Score

8.2 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

The AMQP 1.0 parser accepts an array of zero-width list0 elements with a 32-bit count and loops without consuming input. SASL frames are parsed before authentication, so an unauthenticated attacker who can reach an AMQP listener with AMQP 1.0 enabled (port 5672) can send a frame of about 19 bytes that makes the reader build a list of roughly 4 billion elements. Memory runs out, the Erlang VM stops, and every protocol and tenant on the node loses service.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.