Feed/CVE-2023-46118
CVE-2023-46118MEDIUMCVSS 4.9

RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API

Published Jun 30, 2026·Updated Jun 30, 2026

NVD Description

### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service

Affected Packages (1)

rabbit_commonHEX
From 3.12.0
Fixed in 3.12.7

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free