CVE-2026-67232
RabbitMQ Web MQTT plugin inflates compressed WebSocket frames without a size limit
Technology
RabbitMQ
CVSS Score
8.2 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
The Web MQTT plugin negotiates permessage-deflate on its WebSocket listener without setting a maximum frame size, and each frame is inflated before any MQTT packet is read. An unauthenticated attacker who can reach the Web MQTT ports (15675 or 15676) can send a frame of a few kilobytes that inflates to gigabytes and crashes the node. Precondition: rabbitmq_web_mqtt enabled, which is not the default.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.