Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66072

Опубликовано: 23 сент. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and resolve_offset_spec frames, with no whitelist and no existing guard. An authenticated stream client with read access to any stream can crash the broker node. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol user with read access to at least one stream. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

A flaw was found in RabbitMQ. An authenticated stream client with read access to any stream can exploit a vulnerability in the get_chunk_selector/1 function. This function processes a client-supplied chunk_selector property without proper validation, leading to an atom table exhaustion. Successful exploitation can cause the RabbitMQ broker node to crash, resulting in a Denial of Service (DoS).

Отчет

Red Hat rates this flaw MODERATE in products that ship affected RabbitMQ builds. With the stream plugin enabled, an authenticated client with read access to a stream can supply a crafted chunk selector, exhaust the broker’s atom table, and crash the node.

Меры по смягчению последствий

Disable the stream plugin if unused, and restrict stream access to trusted clients.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverNot affected
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2539758rabbitmq-server: RabbitMQ: Denial of Service via atom table exhaustion in stream chunk_selector

EPSS

Процентиль: 24%
0.0033
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and resolve_offset_spec frames, with no whitelist and no existing guard. An authenticated stream client with read access to any stream can crash the broker node. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol user with read access to at least one stream. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

nvd
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and resolve_offset_spec frames, with no whitelist and no existing guard. An authenticated stream client with read access to any stream can crash the broker node. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol user with read access to at least one stream. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

debian
11 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...

github
3 месяца назад

Atom table exhaustion via stream `chunk_selector`

EPSS

Процентиль: 24%
0.0033
Низкий

6.5 Medium

CVSS3