RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
Published Sep 23, 2026
8.2
HIGHCVSS 4.0
EPSS 0.32%
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The enclosing array32 parser at line 148 reads a 4-byte Count from the wire and loops Count times consuming B bytes each , with B = 0, no input is consumed and the loop builds a list of Count empty elements bounded only by the 32-bit field. The SASL-mechanisms / SASL-init frame is parsed by amqp10_framing:decode_bin/1 from rabbit_amqp_reader.erl:412 before authentication completes. The pre-auth incoming_max_frame_size (default 8192 bytes) caps the frame, not the Count field, so a 19-byte payload with Count = 0xFFFFFFFF is accepted. No max_heap_size is set on the reader process. An unauthenticated network attacker can crash any RabbitMQ node that has the AMQP 1.0 listener enabled (default port 5672) by sending a single ~19-byte frame. The reader process attempts to build a list of ~4 billion empty elements, exhausting heap memory and terminating the Erlang VM. All tenants and protocols on the node lose service. Preconditions include Network reachability to the AMQP listener (port 5672, enabled by default) No authentication required. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Affected products
-
Affected
- ≥ 3.13.0, < 3.13.15
- ≥ 4.0.0, < 4.0.20
- ≥ 4.1.0, < 4.1.11
- ≥ 4.2.0, < 4.2.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rabbitmq | Rabbitmq-Server | unknown | Affected
|
No data.
No data.
Red Hat Hardened Images
rabbitmq-server4-3-main-4.3.6-1.hum1
Fixed · RHSA-2026:67552
Red Hat Hardened Images
rabbitmq-server4.2
Will not fix
Red Hat OpenStack Platform 13 (Queens)
rabbitmq-server
Not affected
Red Hat OpenStack Platform 16.2
rabbitmq-server
Not affected
Red Hat OpenStack Platform 17.1
rabbitmq-server
Not affected
Red Hat OpenStack Platform 18.0
rabbitmq-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.6-1.hum1 | Fixed | RHSA-2026:67552 |
| Red Hat Hardened Images | rabbitmq-server4.2 | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 18.0 | rabbitmq-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat rates this flaw IMPORTANT in products that ship affected RabbitMQ builds. An unauthenticated network client can send a small crafted AMQP 1.0 frame to an exposed listener, causing memory exhaustion that crashes the broker node and interrupts service for all tenants and protocols.
Red Hat mitigation
Restrict untrusted network access to AMQP listeners; disable AMQP 1.0 support if unused.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-66079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2539722 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85627 Advisory
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c66h-hf5j-8jf9 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-66079
- https://www.cve.org/CVERecord?id=CVE-2026-66079
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data