Messaging and Streaming Broker Vulnerability in RabbitMQ
CVE-2026-66072
6MEDIUM
What is CVE-2026-66072?
In RabbitMQ, an issue was identified where the get_chunk_selector/1 function allows processing of unfiltered, client-supplied input when handling post-auth subscribe and resolve_offset_spec frames. This vulnerability can lead to a broker crash if an authenticated stream client, with read access to any stream, sends crafted input that triggers the failure. Users should upgrade to the fixed versions (3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.1) to mitigate risks associated with this vulnerability.
Affected Version(s)
rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15
rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20
rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11
