Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67419

RabbitMQ topic bindings with repeated # segments cause combinatorial routing work

Technology

RabbitMQ

CVSS Score

7.1 / 10.0

Affected Versions

4.3.0 to 4.3.4

Upstream Fix

4.3.5 (public)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

An authenticated user who can bind a queue to a topic exchange and publish to it can put consecutive # segments in a binding key, which makes the topic matchers revisit the same states without memoization. CPU and memory cost grow combinatorially and can disrupt routing for every tenant on the broker.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.3.0 to 4.3.4, you need this patch. Book a discovery call to get covered.