### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
Update rabbit_common to 3.12.7; rabbit_common to 3.11.24 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API affects rabbit_common (erlang), rabbit_common (erlang). Severity is medium. ### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
AI coding agents often install or upgrade packages automatically in erlang. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| rabbit_commonerlang | >=3.12.0,<3.12.7 |
### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
Update rabbit_common to 3.12.7; rabbit_common to 3.11.24 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API affects rabbit_common (erlang), rabbit_common (erlang). Severity is medium. ### Summary Responsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. ### Details An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ### Impact Denial of Service
AI coding agents often install or upgrade packages automatically in erlang. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| rabbit_commonerlang | >=3.12.0,<3.12.7 |
| 3.12.7 |
| rabbit_commonerlang | >=3.11.0,<3.11.24 | 3.11.24 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 3.12.7 |
| rabbit_commonerlang | >=3.11.0,<3.11.24 | 3.11.24 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard