Bug 2539784 (CVE-2026-67235) - CVE-2026-67235 rabbitmq-server: RabbitMQ: Denial of Service via AMQP 0-9-1 body size validation bypass
Summary: CVE-2026-67235 rabbitmq-server: RabbitMQ: Denial of Service via AMQP 0-9-1 bo...
Keywords:
Status: NEW
Alias: CVE-2026-67235
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540099
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-23 20:52 UTC by OSIDB Bzimport
Modified: 2026-09-24 14:08 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-23 20:52:57 UTC
RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assembly completed. By declaring body_size = 2^63-1 and then streaming fragments, a client ensured that check_msg_size never fired, so the accumulated body size went unbounded. A reader process accumulates memory until the memory alarm fires, degrading all publishers cluster-wide, or until the node runs out of memory. The memory alarm provides only partial mitigation, since it is reactive rather than preventive. AMQP 0-9-1 is the most widely used protocol, and any publisher can trigger this condition. Preconditions include Any authenticated AMQP 0-9-1 client with publish permission can exploit this.. This issue is fixed in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.


Note You need to log in before you can comment on or make changes to this bug.