CVE-2026-67235
RabbitMQ AMQP 0-9-1 body size is not checked until the message is complete
Technology
RabbitMQ
CVSS Score
7.1 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
The body size declared in an AMQP 0-9-1 content header was not validated against max_message_size, and the size check ran only once the body was assembled. A publisher that declares a huge body and keeps streaming fragments grows the reader's memory until the memory alarm blocks publishers across the cluster or the node runs out of memory. Any authenticated client with publish permission can trigger it.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.