Resource Exhaustion Vulnerability in RabbitMQ Messaging Broker by Pivotal
CVE-2026-67240
2.3LOW
What is CVE-2026-67240?
RabbitMQ, a messaging and streaming broker, contains a resource exhaustion vulnerability in versions before 4.2.7 and 4.3.1. The issue arises from how the system handles pattern matching for SQL filters, allowing an authenticated AMQP 1.0 consumer to exploit the vulnerability with crafted LIKE filters. The impact can result in significant CPU load, particularly when processing large messages across multiple sessions. This backtracking-driven amplification can lead to performance degradation and service disruption, making it crucial for users to upgrade to the patched versions promptly.
Affected Version(s)
rabbitmq-server >= 4.2.0, < 4.2.7 < 4.2.0, 4.2.7
rabbitmq-server >= 4.3.0, < 4.3.1 < 4.3.0, 4.3.1
