Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196366 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-57220
broadcom · rabbitmq_server

RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS

Description

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.

Affected Products

VendorProductVersions
broadcomrabbitmq_server>= 4.2.0, < 4.2.6

References

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35q(x_refsource_CONFIRM)
  • https://github.com/rabbitmq/rabbitmq-server/pull/16171(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/pull/16173(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/commit/595ec28fa1621b1f2c28124e4e0466a8ad963547(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/commit/773a49c4921e8be990262a2d609c35916825679e(x_refsource_MISC)
  • https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6(x_refsource_MISC)

Related News (3 articles)

Tier A
Microsoft MSRC40d ago
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
→ No new info (linked only)
Tier C
VulDB44d ago
CVE-2026-57220 | RabbitMQ up to 4.2.5 Stream Listener resource consumption
→ No new info (linked only)
Tier B
BSI Advisories59d ago
[NEU] [hoch] RabbitMQ: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-770
PublishedJul 10, 2026
Trending Score1
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Multiple vulnerabilities in Broadcom VMware Tanzu Greenplum and RabbitMQ products
NONECVE-2026-15380
Local privilege escalation in Symantec ITMS
CRITICALPRE-CVE
Critical Vulnerabilities in VMware Tanzu for MySQL on Kubernetes
NONECVE-2026-15379
Arbitrary File Read as SYSTEM in Symantec ITMS
NONECVE-2026-11626
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026