Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67235

RabbitMQ AMQP 0-9-1 body size is not checked until the message is complete

Technology

RabbitMQ

CVSS Score

7.1 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

The body size declared in an AMQP 0-9-1 content header was not validated against max_message_size, and the size check ran only once the body was assembled. A publisher that declares a huge body and keeps streaming fragments grows the reader's memory until the memory alarm blocks publishers across the cluster or the node runs out of memory. Any authenticated client with publish permission can trigger it.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.