Responsibly disclosed by @NSEcho.
HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages.
An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism.
A PoC was provided to Team RabbitMQ privately.
Denial of Service
{
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-400"
],
"nvd_published_at": "2023-10-25T18:17:36Z",
"github_reviewed_at": "2026-06-30T16:39:12Z"
}