CVE-2026-57212EPSS p35.4%
CVE-2026-57212CVE-2026-57212
broadcom / rabbitmq_server
Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
Scoring
| CVSS | 7.7 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
| EPSS | 0.43% probability of exploitation · percentile 35.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |