RabbitMQ Messaging Broker Vulnerability Affects Multiple Versions
CVE-2026-67419

7.1HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67419?

An authenticated user of RabbitMQ, prior to version 4.3.5, can exploit a flaw in the binding key mechanism. By using consecutive '#' segments in a binding key, the user can instigate duplicate routing actions, leading to increased CPU usage and memory pressure. This may disrupt the routing functions for all tenants, causing significant performance degradation. The issue has been addressed in version 4.3.5, which resolves these vulnerabilities effectively.

Affected Version(s)

rabbitmq-server < 4.3.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.