Количество 5
Количество 5
CVE-2026-67419
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5.
CVE-2026-67419
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5.
CVE-2026-67419
RabbitMQ: Consecutive topic wildcards cause combinatorial routing work
CVE-2026-67419
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authe ...
GHSA-h964-v5mf-22cq
Consecutive topic wildcards cause combinatorial routing work
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-67419 RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5. | 0% Низкий | 8 дней назад | ||
CVE-2026-67419 RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5. | 0% Низкий | 8 дней назад | ||
CVE-2026-67419 RabbitMQ: Consecutive topic wildcards cause combinatorial routing work | 0% Низкий | 5 дней назад | ||
CVE-2026-67419 RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authe ... | 0% Низкий | 8 дней назад | ||
GHSA-h964-v5mf-22cq Consecutive topic wildcards cause combinatorial routing work | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу