Описание
STOMP pre-authentication frame size limit is not enforced
Vulnerability
In rabbit_stomp.hrl (lines 60-61), two frame size constants are defined:
The intent is clearly to limit unauthenticated STOMP connections to 64KB frames while allowing authenticated connections up to 4MB. However, DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED is never referenced anywhere in the codebase.
In rabbit_stomp_reader.erl (line 98), only the 4MB limit is applied to ALL connections regardless of authentication state:
A grep of the entire rabbitmq_stomp directory confirms zero references to DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED outside its definition in the .hrl file.
Impact
- Pre-authentication resource exhaustion: Unauthenticated STOMP clients can send frames up to 4MB (should be capped at 64KB)
- Memory amplification: An attacker opening many unauthenticated connections, each sending 4MB frames, can exhaust server memory
- Defense-in-depth failure: The intended security control exists as dead code, providing a false sense of security
Note: This is a lower-severity finding since 4MB per connection alone is not sufficient for OOM on most systems. The risk increases with many concurrent unauthenticated connections.
Comparison with MQTT
The MQTT plugin correctly implements separate limits:
mqtt.max_packet_size_unauthenticated = 65536(enforced for CONNECT packets)mqtt.max_packet_size_authenticated = 16777216(enforced for post-auth packets)
Both are actively checked in rabbit_mqtt_packet.erl via check_max_packet_size/2. The STOMP plugin should follow the same pattern.
Affected Code
deps/rabbitmq_stomp/include/rabbit_stomp.hrl:61— dead constant definitiondeps/rabbitmq_stomp/src/rabbit_stomp_reader.erl:98— only usesDEFAULT_MAX_FRAME_SIZE
Suggested Fix
Add a separate frame size check for unauthenticated connections in rabbit_stomp_reader.erl:
Then switch from MaxFrameSizeUnauth to MaxFrameSizeAuth after successful CONNECT/authentication.
Пакеты
rabbitmq
>= 3.13.0, < 3.13.19
3.13.19
rabbitmq
>= 4.0.0, < 4.0.24
4.0.24
rabbitmq
>= 4.1.0, < 4.1.15
4.1.15
rabbitmq
>= 4.2.0, < 4.2.10
4.2.10
rabbitmq
>= 4.3.0, < 4.3.5
4.3.5
6.3 Medium
CVSS4
Дефекты
6.3 Medium
CVSS4