Disclosure summary
RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service. rabbitMQ 4.3.1 with rabbitmqstreammanagement enabled accepts PUT /api/stream/super-streams/{vhost}/{name} requests from an authenticated management user that can access the target vhost. When the request body contains the binding-keys field, the handler parses the attacker-controlled comma-separated string and builds the full stream-name list before checking whether the user has permission to configure the resulting streams. A low-privileged management user with vhost access but no configure, write, or read permission can therefore force large transient allocations before the resource permission check. In a 768 MB memory-limited container, one HTTP PUT with about 4.5 MB of JSON body killed the RabbitMQ container with Docker state exited true An authenticated low-privileged management user can kill a memory-limited RabbitMQ node with one HTTP This issue is fixed in versions 4.3.3, 4.2.9, and 4.1.11.
Source-reported weakness categories
CWE-400
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-67408
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| broadcom | rabbitmq_server | * {"versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.3"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Patch
- github.com — Patch
- github.com — Release Notes
- github.com — Release Notes
- github.com — Exploit, Vendor Advisory
- github.com — Exploit, Vendor Advisory
PUBLISHED 2026-09-25T13:17:12-04:00
MODIFIED 2026-10-08T11:33:05-04:00
INGESTED 2026-10-10T20:45:41-04:00