GHSA-w6cq-9cf4-gqpg

Suggest an improvement
Source
https://github.com/advisories/GHSA-w6cq-9cf4-gqpg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w6cq-9cf4-gqpg/GHSA-w6cq-9cf4-gqpg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w6cq-9cf4-gqpg
Aliases
Published
2026-06-30T16:39:12Z
Modified
2026-06-30T16:45:17.913261799Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
Details

Summary

Responsibly disclosed by @NSEcho.

HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages.

Details

An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism.

A PoC was provided to Team RabbitMQ privately.

Impact

Denial of Service

Database specific
{
    "github_reviewed": true,
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-400"
    ],
    "nvd_published_at": "2023-10-25T18:17:36Z",
    "github_reviewed_at": "2026-06-30T16:39:12Z"
}
References

Affected packages

Hex / rabbit_common

Package

Name
rabbit_common
Purl
pkg:hex/rabbit_common

Affected ranges

Type
SEMVER
Events
Introduced
3.12.0
Fixed
3.12.7

Affected versions

3.*
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w6cq-9cf4-gqpg/GHSA-w6cq-9cf4-gqpg.json"

Hex / rabbit_common

Package

Name
rabbit_common
Purl
pkg:hex/rabbit_common

Affected ranges

Type
SEMVER
Events
Introduced
3.11.0
Fixed
3.11.24

Affected versions

3.*
3.11.0
3.11.1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.11.10
3.11.11
3.11.12
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.20
3.11.21
3.11.22
3.11.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w6cq-9cf4-gqpg/GHSA-w6cq-9cf4-gqpg.json"