Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-66079— RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS

Quick assessment

Affected
rabbitmq rabbitmq-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RabbitMQ 是一个消息代理和流处理中间件。在版本 3.13.15、4.0.20、4.1.11 和 4.2.6 之前,对于构造函数 0x45(list0)的 函数会返回一个字节宽度 B = 0 的元素。位于第 148 行的 解析器会从网络输入中读取 4 字节的 Count 值,并循环 Count 次,每次消耗 B 字节。当 B = 0 时,不会消耗任何输入数据,而循环会构建一个包含 Count 个空元素的列表,其长度仅受 32 位字段的限制。 在认证完成之前,来自 第 412 行的 函数会解析 SASL 机制(

CVSS 8.2 · High EPSS 0.32% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66079

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
Source: CVE Program / CVE List V5
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The enclosing array32 parser at line 148 reads a 4-byte Count from the wire and loops Count times consuming B bytes each , with B = 0, no input is consumed and the loop builds a list of Count empty elements bounded only by the 32-bit field. The SASL-mechanisms / SASL-init frame is parsed by amqp10_framing:decode_bin/1 from rabbit_amqp_reader.erl:412 before authentication completes. The pre-auth incoming_max_frame_size (default 8192 bytes) caps the frame, not the Count field, so a 19-byte payload with Count = 0xFFFFFFFF is accepted. No max_heap_size is set on the reader process. An unauthenticated network attacker can crash any RabbitMQ node that has the AMQP 1.0 listener enabled (default port 5672) by sending a single ~19-byte frame. The reader process attempts to build a list of ~4 billion empty elements, exhausting heap memory and terminating the Erlang VM. All tenants and protocols on the node lose service. Preconditions include Network reachability to the AMQP listener (port 5672, enabled by default) No authentication required. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rabbitmq rabbitmq-server >= 3.13.0, < 3.13.15 -

II. Public POCs for CVE-2026-66079

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66079

请登录查看更多情报信息。

Vendor Pages for CVE-2026-66079 (1)

Other References for CVE-2026-66079 (1)

Same Patch Batch · rabbitmq · 2026-09-23 · 25 CVEs total

CVE-2026-67404 9.2 CRITICAL RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch
CVE-2026-67231 9.1 CRITICAL RabbitMQ: Trust-store whitelist by Issuer+Serial only
CVE-2026-67232 8.2 HIGH RabbitMQ: Web-MQTT decompression bomb
CVE-2026-66070 7.6 HIGH RabbitMQ: CORS * reflects Origin with Allow-Credentials
CVE-2026-66077 7.3 HIGH RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
CVE-2026-67235 7.1 HIGH RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size
CVE-2026-67238 7.1 HIGH RabbitMQ: Atom-table exhaustion via reply-to queue name decoding
CVE-2026-67229 6.9 MEDIUM RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata
CVE-2026-67228 6.9 MEDIUM RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component
CVE-2026-66067 6.0 MEDIUM RabbitMQ: Stream protocol skips per vhost per user connection limits
CVE-2026-66072 6.0 MEDIUM RabbitMQ: Atom table exhaustion via stream `chunk_selector`
CVE-2026-67220 6.0 MEDIUM RabbitMQ: JMS topic exchange erl_scan atom exhaustion
CVE-2026-67219 6.0 MEDIUM RabbitMQ: Consistent-hash exchange unbounded weight
CVE-2026-66074 6.0 MEDIUM RabbitMQ: ReDoS via management API ?name= filter
CVE-2026-66080 5.9 MEDIUM RabbitMQ: Super-stream partitions unbounded allocation
CVE-2026-67221 5.9 MEDIUM RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords
CVE-2026-66068 5.6 MEDIUM RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs
CVE-2026-67405 5.3 MEDIUM RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)
CVE-2026-66069 2.3 LOW RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics
CVE-2026-66076 2.3 LOW RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure

Showing top 20 of 25 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-66079

No comments yet


Leave a comment