Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88266.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-88266
Upstream
Published
2026-05-13T19:17:30Z
Modified
2026-09-02T06:51:55Z
Summary
CVE-2026-8466 affecting package rabbitmq-server for versions less than 3.13.7-5
Details

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing.

cowboyreq:readpart/3 in src/cowboyreq.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When cowmultipart:parseheaders/2 returns more or {more, Buffer2}, the function reads up to Length bytes (default 64 KB) from the request body and recurses with the enlarged buffer. There is no equivalent of the bytesize(Acc) > Length guard present in the sibling function readpartbody/4. An unauthenticated attacker can send a multipart/form-data request whose body never yields a complete header section — for example, a body that never contains the advertised boundary delimiter, or one whose header lines never contain \r\n\r\n — and force the server process to accumulate memory linearly with the bytes the protocol layer is willing to deliver. A handful of concurrent such uploads is sufficient to exhaust BEAM memory.

This issue affects cowboy from 2.0.0 before 2.15.0.

References

Affected packages

Azure Linux:3 / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:rpm/azure-linux/rabbitmq-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.7-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-88266.json"