Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67232

RabbitMQ Web MQTT plugin inflates compressed WebSocket frames without a size limit

Technology

RabbitMQ

CVSS Score

8.2 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

The Web MQTT plugin negotiates permessage-deflate on its WebSocket listener without setting a maximum frame size, and each frame is inflated before any MQTT packet is read. An unauthenticated attacker who can reach the Web MQTT ports (15675 or 15676) can send a frame of a few kilobytes that inflates to gigabytes and crashes the node. Precondition: rabbitmq_web_mqtt enabled, which is not the default.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.