Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66080

Опубликовано: 23 сент. 2026
Источник: redhat
CVSS3: 4.9

Описание

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000) allocates roughly 8GB. Preconditions include The rabbitmq_stream_management plugin must be enabled. The caller needs the management tag and access to the target vhost.. This issue is fixed in versions 4.1.11, 4.2.6, and 4.3.0.

A flaw was found in RabbitMQ. A highly privileged remote attacker, with the rabbitmq_stream_management plugin enabled and access to the target vhost, can exploit an unbounded allocation vulnerability in the super-stream partitions. This allows the attacker to allocate a large amount of memory, leading to a Denial of Service (DoS) due to resource exhaustion.

Отчет

Red Hat rates this flaw MODERATE in products that ship affected RabbitMQ builds. With the stream-management plugin enabled, a management-tagged user with access to a virtual host can request an excessive number of super-stream partitions, exhausting broker memory and causing a denial of service.

Меры по смягчению последствий

Restrict management-tagged accounts and disable stream management where it is not needed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverNot affected
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2539757rabbitmq-server: RabbitMQ: Denial of Service via unbounded super-stream partition allocation

4.9 Medium

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000) allocates roughly 8GB. Preconditions include The rabbitmq_stream_management plugin must be enabled. The caller needs the management tag and access to the target vhost.. This issue is fixed in versions 4.1.11, 4.2.6, and 4.3.0.

nvd
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000) allocates roughly 8GB. Preconditions include The rabbitmq_stream_management plugin must be enabled. The caller needs the management tag and access to the target vhost.. This issue is fixed in versions 4.1.11, 4.2.6, and 4.3.0.

debian
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11 ...

github
3 месяца назад

Super-stream partitions unbounded allocation

4.9 Medium

CVSS3