WebSocket Compression Vulnerability in RabbitMQ Messaging Broker
CVE-2026-67232

8.2HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-67232?

A vulnerability exists in RabbitMQ's handling of WebSocket connections that allows unauthenticated attackers to exploit the permessage-deflate feature. By sending a specially crafted highly-compressed WebSocket frame, an attacker can trigger the server to inflate the payload into an excessively large size, consuming significant memory resources and potentially crashing the RabbitMQ node. This occurs without any form of authentication, making it a considerable risk for users utilizing the web-MQTT plugin in their applications. The vulnerability has been addressed in RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.