Aller au contenu

Fiche vulnérabilité

CVE-2026-57212 : faille élevée broadcom rabbitmq server (CVSS 7.7)

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

En bref

Sévérité
Élevée (CVSS 7.7)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
10 juil. 2026
Dernière mise à jour
13 juil. 2026

Produits concernés

  • broadcom rabbitmq server

Références

Rechercher une autre vulnérabilité dans la base CVE