CVE-2026-66079
RabbitMQ AMQP 1.0 parser can be crashed before authentication with a 19-byte frame
Technology
RabbitMQ
CVSS Score
8.2 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
The AMQP 1.0 parser accepts an array of zero-width list0 elements with a 32-bit count and loops without consuming input. SASL frames are parsed before authentication, so an unauthenticated attacker who can reach an AMQP listener with AMQP 1.0 enabled (port 5672) can send a frame of about 19 bytes that makes the reader build a list of roughly 4 billion elements. Memory runs out, the Erlang VM stops, and every protocol and tenant on the node loses service.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.