Memory Allocation Vulnerability in RabbitMQ Messaging Broker
CVE-2026-67235

7.1HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-67235?

A memory allocation issue affects certain versions of RabbitMQ, where the content-header BodySize was stored without proper validation, allowing for unbounded memory consumption. Exploitation can occur when an authenticated AMQP 0-9-1 client with publish permission streams data in a way that circumvents necessary size checks, leading to potential cluster-wide degradation as memory fills up. This vulnerability can affect the overall operation of the message broker, necessitating immediate action for users on affected versions to upgrade to secure releases.

Affected Version(s)

rabbitmq-server >= 4.2.0, < 4.2.6 < 4.2.0, 4.2.6

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.