AZL-105314

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105314.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105314
Upstream
Published
2026-09-25T17:17:13Z
Modified
2026-10-02T05:34:59Z
Summary
CVE-2026-67413 affecting package rabbitmq-server 3.13.7-9
Details

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding expression whose LIKE evaluator expanded percent and underscore wildcards into overlapping PCRE fragments. It executed those fragments with raw re:run/3 without match or recursion limits, allowing an authenticated tenant that can bind and publish to consume broker scheduler CPU and deny service with pathological selectors. This issue is fixed in versions 4.0.23, 4.1.14, 4.2.9, and 4.3.3.

References

Affected packages

Azure Linux:3 / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:rpm/azure-linux/rabbitmq-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.13.7-9

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105314.json"