PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67225 rabbitmq CVE debrief

A vulnerability in RabbitMQ, a messaging and streaming broker, allows a remote client to cause excessive memory pressure and denial of service by declaring an oversized frame when the stream plugin is enabled. This issue affects versions from 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6. The vulnerability can lead to denial of service attacks, impacting the availability of messaging and streaming services. Defenders should prioritize verifying exposure, assessing impact, and applying patches or updates to prevent or mitigate potential attacks.

Vendor
rabbitmq
Product
rabbitmq-server
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

RabbitMQ administrators and users, especially those using the stream plugin, should assess their exposure and take necessary actions to prevent or mitigate potential denial of service attacks.

Why it matters

This vulnerability in RabbitMQ can lead to denial of service attacks, impacting the availability of messaging and streaming services. Defenders should prioritize verifying exposure, assessing impact, and applying patches or updates to prevent or mitigate potential attacks.

  • Denial of service through excessive memory pressure
  • Potential disruption of messaging and streaming services
  • Need for verification of RabbitMQ version and exposure
  • Prioritization of patching or updating RabbitMQ deployments

Technical summary

The vulnerability occurs in the stream protocol of RabbitMQ, where the FrameMax value negotiated during the Tune handshake is not compared with an inbound frame's declared length before buffering the frame. This allows a remote client to cause excessive memory pressure and denial of service. The vulnerability can lead to denial of service attacks, impacting the availability of messaging and streaming services. Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their RabbitMQ deployments, especially those using the stream plugin.

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of this vulnerability on their RabbitMQ deployments, especially those using the stream plugin.

Recommended defensive actions

  • Verify RabbitMQ version and assess exposure
  • Review and apply patches or updates
  • Monitor for suspicious activity
  • Consider compensating controls
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including affected versions and fixed versions. However, additional information on exploitation or victim impact is not available. The vulnerability occurs in the stream protocol of RabbitMQ, where the FrameMax value negotiated during the Tune handshake is not compared with an inbound frame's declared length before buffering the frame. This allows a remote client to cause excessive memory pressure and denial of service. RabbitMQ administrators and users, especially 3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-67225 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-67225

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-67225 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67225

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.