HIGH 7.1 NVD
CVE-2026-67419
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecuti
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same trie-node and routing-key-suffix states without memoization. The matcher materializes duplicate destinations before deduplication, causing combinatorial CPU work and memory pressure that can disrupt routing for all tenants. This vulnerability is fixed in 4.3.5.
References
- https://github.com/rabbitmq/rabbitmq-server/commit/c5ed7c4e97e02be688730803604cc7a88dbe486
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.5
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-25 via NVD.
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.