CVE-2026-67419
— UNSCOREDpublic exploit availablePublished 2026-09-25 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5.
Weaknesses
CWE-407, CWE-1333
Public exploit & PoC references
- https://github.com/rabbitmq/rabbitmq-server/commit/c5ed7c4e97e02be688730803604cc7a88dbe4864
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.5
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
All references
- https://github.com/rabbitmq/rabbitmq-server/commit/c5ed7c4e97e02be688730803604cc7a88dbe4864
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.5
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100700PoC
- UNSCOREDCVE-2026-101903PoC
- UNSCOREDCVE-2026-101906PoC
- MEDIUMCVE-2026-102270PoC
- MEDIUMCVE-2026-102277PoC
- MEDIUMCVE-2026-19668
- LOWCVE-2026-44639PoC
- MEDIUMCVE-2026-54461PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.