CVE-2026-57212
rabbitmq rabbitmq-server, rabbitmq server
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
- CVSS
- 7.1
- EPSS
- 0.40% 32.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11