RabbitMQ: Web-MQTT decompression bomb
Published Sep 23, 2026
8.2
HIGHCVSS 4.0
EPSS 0.37%
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does not set max_frame_size, so cowboy's default of infinity applies. cowlib's cow_ws:parse_payload/9 calls zlib:inflate/2 on the compressed payload with no output-size limit. An attacker can negotiate permessage-deflate during the WebSocket upgrade and send a frame containing a zlib bomb (e.g. 50 KB → 5 GB). Decompression occurs in the connection process before websocket_handle/2 ever sees the MQTT bytes. An unauthenticated attacker can crash a RabbitMQ node running the Web-MQTT plugin by sending a single highly-compressed WebSocket frame (a few KB on the wire) that inflates to gigabytes in memory. The cowboy WebSocket handler decompresses the entire frame before the MQTT CONNECT packet is processed, so no credentials are required. Preconditions include rabbitmq_web_mqtt plugin enabled (not default, but common for browser clients) Network reachability to port 15675/15676 No authentication required. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Affected products
-
- Version >= 3.13.0, < 3.13.15StatusaffectedConstraints-
- Version >= 4.0.0, < 4.0.20StatusaffectedConstraints-
- Version >= 4.1.0, < 4.1.11StatusaffectedConstraints-
- Version >= 4.2.0, < 4.2.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rabbitmq | Rabbitmq-Server | n/a |
|
No data.
No data.
Red Hat Hardened Images
rabbitmq-server4-3-main-4.3.6-1.hum1
Fixed · RHSA-2026:67552
Red Hat Hardened Images
rabbitmq-server4.2
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.6-1.hum1 | Fixed | RHSA-2026:67552 |
| Red Hat Hardened Images | rabbitmq-server4.2 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 24, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.37% (0.00366) | 28.18th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.37% (0.00366) | 28.09th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-67232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2539787 Issue Tracking
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.0 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gmgx-hhg5-43gr x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-67232
- https://www.cve.org/CVERecord?id=CVE-2026-67232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-67232 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2539787 | Issue Tracking | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.0 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gmgx-hhg5-43gr | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-67232 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-67232 |
Change history (0)
No recorded changes yet.