Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-67240— RabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcard

Quick assessment

Affected
rabbitmq rabbitmq-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RabbitMQ 是一款消息和流处理代理(broker)。在 4.2.7 和 4.3.1 版本之前, 函数将 映射为 ,将 映射为 ,然后仅使用 选项编译以 开头、 结尾的正则表达式。同时,调用 时仅指定 ,未显式设置 。 构造如下形式的模式: ,会被转换为 ,其中包含重叠的惰性量词。整个表达式的上限受限于 字符和 ;由于一个 LIKE 字符串字面量算作一个 token,因此大约可以容纳 2000 个 对。 在 处无条件接受 SQL 过滤器(无需启用任何功能标志),并在 针对每条消息进行评估。OTP 默认的 为 1

CVSS 2.3 · Low EPSS 0.26% · P16
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67240

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcard
Source: CVE Program / CVE List V5
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ -> ., then compiles ^...$ with only [unicode]; re:run is called with only [{capture, none}] - no explicit match_limit. A pattern like %_%_..._%X becomes ^.*?..*?.....*?.X$ with overlapping lazy quantifiers. The whole-expression cap is ?MAX_EXPRESSION_LENGTH=4096 chars / ?MAX_TOKENS=200; a LIKE string literal is one token, so ~2000 %_ pairs fit. SQL filters are accepted unconditionally at rabbit_amqp_session.erl:3264 (no feature flag). Evaluated per-message at rabbit_stream_queue.erl:1439. OTP's default 10M match_limit caps each match at ~100-200 ms (not seconds), and the re NIF yields to the scheduler. An authenticated AMQP 1.0 consumer with read+write on a stream queue can cause ~100-200 ms of CPU per delivered message via a crafted LIKE filter, multiplied across thousands of messages and parallel sessions - a substantial backtracking-driven CPU amplification. Preconditions include AMQP 1.0 with stream queues in use Attacker can attach a receiver with a filter (read permission) and publish messages with long property values (write permission). This issue is fixed in versions 4.2.7 and 4.3.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1333
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rabbitmq rabbitmq-server >= 4.2.0, < 4.2.7 -

II. Public POCs for CVE-2026-67240

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67240

请登录查看更多情报信息。

Other References for CVE-2026-67240 (3)

Same Patch Batch · rabbitmq · 2026-09-23 · 25 CVEs total

CVE-2026-67404 9.2 CRITICAL RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch
CVE-2026-67231 9.1 CRITICAL RabbitMQ: Trust-store whitelist by Issuer+Serial only
CVE-2026-66079 8.2 HIGH RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
CVE-2026-67232 8.2 HIGH RabbitMQ: Web-MQTT decompression bomb
CVE-2026-66070 7.6 HIGH RabbitMQ: CORS * reflects Origin with Allow-Credentials
CVE-2026-66077 7.3 HIGH RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
CVE-2026-67235 7.1 HIGH RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size
CVE-2026-67238 7.1 HIGH RabbitMQ: Atom-table exhaustion via reply-to queue name decoding
CVE-2026-67228 6.9 MEDIUM RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component
CVE-2026-67229 6.9 MEDIUM RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata
CVE-2026-66067 6.0 MEDIUM RabbitMQ: Stream protocol skips per vhost per user connection limits
CVE-2026-66074 6.0 MEDIUM RabbitMQ: ReDoS via management API ?name= filter
CVE-2026-67219 6.0 MEDIUM RabbitMQ: Consistent-hash exchange unbounded weight
CVE-2026-66072 6.0 MEDIUM RabbitMQ: Atom table exhaustion via stream `chunk_selector`
CVE-2026-67220 6.0 MEDIUM RabbitMQ: JMS topic exchange erl_scan atom exhaustion
CVE-2026-66080 5.9 MEDIUM RabbitMQ: Super-stream partitions unbounded allocation
CVE-2026-67221 5.9 MEDIUM RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords
CVE-2026-66068 5.6 MEDIUM RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs
CVE-2026-67405 5.3 MEDIUM RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)
CVE-2026-66075 2.3 LOW RabbitMQ: Monitoring-tag user can restart federation links

Showing top 20 of 25 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-67240

No comments yet


Leave a comment