Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8c4-gvv4-8j3q

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью

Описание

Stream-protocol frame length never validated against frame_max

Origin

This vulnerability was identified by Team RabbitMQ and/or other teams at Broadcom, not via a responsible disclosure from an external researcher.

Impact

The frame size limit negotiated during the stream-protocol handshake is never enforced against the declared length of inbound frames. A client can send a frame whose declared size exceeds the negotiated frame_max, and the broker buffers the frame data before any size check is applied. This produces memory pressure on the node and a potential denial of service. The condition is reachable before authentication over the network.

Description

The stream protocol negotiates a maximum frame size (FrameMax) during the Tune handshake. The negotiated value is stored but never applied to incoming frames. A %% TODO: check max frame size comment in rabbit_stream_core (deps/rabbitmq_stream_common/src/rabbit_stream_core.erl) confirmed the gap: the 4-byte frame size header is read and the frame is buffered without comparing the declared length against frame_max.

Preconditions

The stream plugin must be enabled.

CVSS

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N (6.3, Moderate). Fixed in 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0.

Пакеты

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.13.0, < 3.13.15

3.13.15

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.20

4.0.20

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.11

4.1.11

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.6

4.2.6

EPSS

Процентиль: 23%
0.00324
Низкий

Дефекты

CWE-770

Связанные уязвимости

ubuntu
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's declared length before buffering the frame. With the stream plugin enabled, a remote client could therefore cause excessive memory pressure and denial of service by declaring an oversized frame. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

nvd
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's declared length before buffering the frame. With the stream plugin enabled, a remote client could therefore cause excessive memory pressure and denial of service by declaring an oversized frame. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

debian
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...

EPSS

Процентиль: 23%
0.00324
Низкий

Дефекты

CWE-770