Messaging and Streaming Broker Vulnerability in RabbitMQ
CVE-2026-66072

6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-66072?

In RabbitMQ, an issue was identified where the get_chunk_selector/1 function allows processing of unfiltered, client-supplied input when handling post-auth subscribe and resolve_offset_spec frames. This vulnerability can lead to a broker crash if an authenticated stream client, with read access to any stream, sends crafted input that triggers the failure. Users should upgrade to the fixed versions (3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.1) to mitigate risks associated with this vulnerability.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.