Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xpg-rfmh-grhq

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

STOMP pre-authentication frame size limit is not enforced

Vulnerability

In rabbit_stomp.hrl (lines 60-61), two frame size constants are defined:

-define(DEFAULT_MAX_FRAME_SIZE, 4 * 1024 * 1024). %% 4MB -define(DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED, 65536). %% 64KB

The intent is clearly to limit unauthenticated STOMP connections to 64KB frames while allowing authenticated connections up to 4MB. However, DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED is never referenced anywhere in the codebase.

In rabbit_stomp_reader.erl (line 98), only the 4MB limit is applied to ALL connections regardless of authentication state:

MaxFrameSize = application:get_env(rabbitmq_stomp, max_frame_size, ?DEFAULT_MAX_FRAME_SIZE),

A grep of the entire rabbitmq_stomp directory confirms zero references to DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED outside its definition in the .hrl file.

Impact

  • Pre-authentication resource exhaustion: Unauthenticated STOMP clients can send frames up to 4MB (should be capped at 64KB)
  • Memory amplification: An attacker opening many unauthenticated connections, each sending 4MB frames, can exhaust server memory
  • Defense-in-depth failure: The intended security control exists as dead code, providing a false sense of security

Note: This is a lower-severity finding since 4MB per connection alone is not sufficient for OOM on most systems. The risk increases with many concurrent unauthenticated connections.

Comparison with MQTT

The MQTT plugin correctly implements separate limits:

  • mqtt.max_packet_size_unauthenticated = 65536 (enforced for CONNECT packets)
  • mqtt.max_packet_size_authenticated = 16777216 (enforced for post-auth packets)

Both are actively checked in rabbit_mqtt_packet.erl via check_max_packet_size/2. The STOMP plugin should follow the same pattern.

Affected Code

  • deps/rabbitmq_stomp/include/rabbit_stomp.hrl:61 — dead constant definition
  • deps/rabbitmq_stomp/src/rabbit_stomp_reader.erl:98 — only uses DEFAULT_MAX_FRAME_SIZE

Suggested Fix

Add a separate frame size check for unauthenticated connections in rabbit_stomp_reader.erl:

%% Before authentication completes, use the unauthenticated limit MaxFrameSizeUnauth = application:get_env(rabbitmq_stomp, max_frame_size_unauthenticated, ?DEFAULT_MAX_FRAME_SIZE_UNAUTHENTICATED), MaxFrameSizeAuth = application:get_env(rabbitmq_stomp, max_frame_size, ?DEFAULT_MAX_FRAME_SIZE),

Then switch from MaxFrameSizeUnauth to MaxFrameSizeAuth after successful CONNECT/authentication.

Пакеты

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.13.0, < 3.13.19

3.13.19

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.24

4.0.24

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.15

4.1.15

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.10

4.2.10

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.3.0, < 4.3.5

4.3.5

6.3 Medium

CVSS4

Дефекты

CWE-770

6.3 Medium

CVSS4

Дефекты

CWE-770