Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67408

RabbitMQ stream management lets a low-privilege user force large allocations through super stream binding keys

Technology

RabbitMQ

CVSS Score

7.1 / 10.0

Affected Versions

4.1.0 to 4.1.10; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2

Upstream Fix

4.2.9 and 4.3.3 (public); 4.1.11 (commercial)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

With rabbitmq_stream_management enabled, PUT /api/stream/super-streams/{vhost}/{name} builds the full list of stream names from the binding-keys field before checking permissions. A management user with access to the vhost but no configure, write or read permission can force large allocations; the advisory reports a single request of about 4.5 MB killing a node in a 768 MB container.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.1.0 to 4.1.10; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2, you need this patch. Book a discovery call to get covered.