{"id":"CVE-2026-67235","published":"2026-09-23T21:17:01.227","lastModified":"2026-09-24T16:17:09.667","description":"RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assembly completed. By declaring body_size = 2^63-1 and then streaming fragments, a client ensured that check_msg_size never fired, so the accumulated body size went unbounded. A reader process accumulates memory until the memory alarm fires, degrading all publishers cluster-wide, or until the node runs out of memory. The memory alarm provides only partial mitigation, since it is reactive rather than preventive. AMQP 0-9-1 is the most widely used protocol, and any publisher can trigger this condition. Preconditions include Any authenticated AMQP 0-9-1 client with publish permission can exploit this.. This issue is fixed in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.0","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q8g2-pc7m-m3jw","tags":[]}],"exploitRefs":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.0","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q8g2-pc7m-m3jw","tags":[]}],"hasPoc":true,"ai":null}