CVE-2026-57220
Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- broadcom/rabbitmq server
- Source
- security-advisories@github.com
References
- https://github.com/rabbitmq/rabbitmq-server/commit/595ec28fa1621b1f2c28124e4e0466a8ad963547Patch
- https://github.com/rabbitmq/rabbitmq-server/commit/773a49c4921e8be990262a2d609c35916825679ePatch
- https://github.com/rabbitmq/rabbitmq-server/pull/16171Issue Tracking, Patch
- https://github.com/rabbitmq/rabbitmq-server/pull/16173Issue Tracking, Patch
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6Release Notes
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35qExploit, Vendor Advisory
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35qExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.