Back

HIGH

RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS

Published Sep 23, 2026

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The enclosing array32 parser at line 148 reads a 4-byte Count from the wire and loops Count times consuming B bytes each , with B = 0, no input is consumed and the loop builds a list of Count empty elements bounded only by the 32-bit field. The SASL-mechanisms / SASL-init frame is parsed by amqp10_framing:decode_bin/1 from rabbit_amqp_reader.erl:412 before authentication completes. The pre-auth incoming_max_frame_size (default 8192 bytes) caps the frame, not the Count field, so a 19-byte payload with Count = 0xFFFFFFFF is accepted. No max_heap_size is set on the reader process. An unauthenticated network attacker can crash any RabbitMQ node that has the AMQP 1.0 listener enabled (default port 5672) by sending a single ~19-byte frame. The reader process attempts to build a list of ~4 billion empty elements, exhausting heap memory and terminating the Erlang VM. All tenants and protocols on the node lose service. Preconditions include Network reachability to the AMQP listener (port 5672, enabled by default) No authentication required. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected products

Remediation

Red Hat statement

Red Hat rates this flaw IMPORTANT in products that ship affected RabbitMQ builds. An unauthenticated network client can send a small crafted AMQP 1.0 frame to an exposed listener, causing memory exhaustion that crashes the broker node and interrupts service for all tenants and protocols.

Red Hat mitigation

Restrict untrusted network access to AMQP listeners; disable AMQP 1.0 support if unused.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 29, 2026
Reserved Jul 23, 2026

CISA Vulnrichment

Updated Sep 29, 2026

NVD

Status Received
Modified Sep 23, 2026

Red Hat

Severity Important
Public date Sep 23, 2026
Bugzilla 2539722

ENISA EUVD

Assigner GitHub_M
Published Sep 23, 2026
Updated Sep 29, 2026

GitHub

No data