CVE-2026-67408
RabbitMQ stream management lets a low-privilege user force large allocations through super stream binding keys
Technology
RabbitMQ
CVSS Score
7.1 / 10.0
Affected Versions
4.1.0 to 4.1.10; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2
Upstream Fix
4.2.9 and 4.3.3 (public); 4.1.11 (commercial)
Published
September 25, 2026
OSSeva Coverage
Fixed upstream
Description
With rabbitmq_stream_management enabled, PUT /api/stream/super-streams/{vhost}/{name} builds the full list of stream names from the binding-keys field before checking permissions. A management user with access to the vhost but no configure, write or read permission can force large allocations; the advisory reports a single request of about 4.5 MB killing a node in a 768 MB container.
Is your RabbitMQ deployment affected?
If you're running 4.1.0 to 4.1.10; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2, you need this patch. Book a discovery call to get covered.