Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-67419
RabbitMQ topic bindings with repeated # segments cause combinatorial routing work
Technology
RabbitMQ
CVSS Score
7.1 / 10.0
Affected Versions
4.3.0 to 4.3.4
Upstream Fix
4.3.5 (public)
Published
September 25, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated user who can bind a queue to a topic exchange and publish to it can put consecutive # segments in a binding key, which makes the topic matchers revisit the same states without memoization. CPU and memory cost grow combinatorially and can disrupt routing for every tenant on the broker.
Is your RabbitMQ deployment affected?
If you're running 4.3.0 to 4.3.4, you need this patch. Book a discovery call to get covered.