Resource Exhaustion Vulnerability in RabbitMQ Messaging Broker by Pivotal
CVE-2026-67240

2.3LOW

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-67240?

RabbitMQ, a messaging and streaming broker, contains a resource exhaustion vulnerability in versions before 4.2.7 and 4.3.1. The issue arises from how the system handles pattern matching for SQL filters, allowing an authenticated AMQP 1.0 consumer to exploit the vulnerability with crafted LIKE filters. The impact can result in significant CPU load, particularly when processing large messages across multiple sessions. This backtracking-driven amplification can lead to performance degradation and service disruption, making it crucial for users to upgrade to the patched versions promptly.

Affected Version(s)

rabbitmq-server >= 4.2.0, < 4.2.7 < 4.2.0, 4.2.7

rabbitmq-server >= 4.3.0, < 4.3.1 < 4.3.0, 4.3.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.