Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-57220

35
FAUCET Score

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.

First published: Jul 10, 2026Last modified: Jul 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 4.2.6CPE matchmatch criteria
cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 20th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0Fixed in: 3.13.7-7

Vendor Advisories (1)

microsoft2026-Jul/CVE-2026-57220Important

RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS

Jul 14, 2026

References

github.com / rabbitmq/rabbitmq-server/commit/595ec28fa1621b1f2c28124e4e0466a8ad963547
Patch
github.com / rabbitmq/rabbitmq-server/commit/773a49c4921e8be990262a2d609c35916825679e
Patch
github.com / rabbitmq/rabbitmq-server/pull/16171
Issue TrackingPatch
github.com / rabbitmq/rabbitmq-server/pull/16173
Issue TrackingPatch
github.com / rabbitmq/rabbitmq-server/releases/tag/v4.2.6
Release Notes
github.com / rabbitmq/rabbitmq-server/security/advisories/GHSA-f364-87q5-j35q
ExploitVendor Advisory