CVE-2026-67413: CWE-1333: Inefficient Regular Expression Complexity in rabbitmq rabbitmq-server
CVE-2026-67413 is a medium severity vulnerability in rabbitmq-server affecting the rabbitmq_jms_topic_exchange plugin. Versions from 4.0.0 up to but not including 4.0.23, 4.1.14, 4.2.9, and 4.3.3 are vulnerable. The issue involves inefficient regular expression complexity in the LIKE evaluator of the x-jms-topic exchange, which can cause excessive CPU consumption and denial of service when processing specially crafted binding expressions. The vulnerability requires authenticated tenant privileges to exploit. Fixed versions are 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
AI Analysis
Technical Summary
RabbitMQ's rabbitmq_jms_topic_exchange plugin (versions 4.0.0 to before 4.0.23, 4.1.14, 4.2.9, and 4.3.3) accepts client-controlled rjms_erlang_selector binding expressions with a LIKE evaluator that expands percent and underscore wildcards into overlapping PCRE fragments. These fragments are executed with raw re:run/3 without match or recursion limits, allowing an authenticated tenant with bind and publish permissions to consume excessive broker scheduler CPU resources, resulting in denial of service. The issue is addressed in versions 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
Potential Impact
An authenticated tenant with permission to bind and publish can craft pathological selectors that cause excessive CPU consumption in the broker scheduler, leading to denial of service conditions. This impacts availability but does not indicate confidentiality or integrity compromise.
Mitigation Recommendations
This vulnerability is fixed in rabbitmq-server versions 4.0.23, 4.1.14, 4.2.9, and 4.3.3. Users should upgrade to these or later versions to remediate the issue. No vendor advisory content contradicts this; therefore, upgrading is the recommended mitigation.
CVE-2026-67413: CWE-1333: Inefficient Regular Expression Complexity in rabbitmq rabbitmq-server
Description
CVE-2026-67413 is a medium severity vulnerability in rabbitmq-server affecting the rabbitmq_jms_topic_exchange plugin. Versions from 4.0.0 up to but not including 4.0.23, 4.1.14, 4.2.9, and 4.3.3 are vulnerable. The issue involves inefficient regular expression complexity in the LIKE evaluator of the x-jms-topic exchange, which can cause excessive CPU consumption and denial of service when processing specially crafted binding expressions. The vulnerability requires authenticated tenant privileges to exploit. Fixed versions are 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
CVSS v4.0
Score 6.0medium
Affected software
rabbitmq
rabbitmq-server
pkg:github/rabbitmq/rabbitmq-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RabbitMQ's rabbitmq_jms_topic_exchange plugin (versions 4.0.0 to before 4.0.23, 4.1.14, 4.2.9, and 4.3.3) accepts client-controlled rjms_erlang_selector binding expressions with a LIKE evaluator that expands percent and underscore wildcards into overlapping PCRE fragments. These fragments are executed with raw re:run/3 without match or recursion limits, allowing an authenticated tenant with bind and publish permissions to consume excessive broker scheduler CPU resources, resulting in denial of service. The issue is addressed in versions 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
Potential Impact
An authenticated tenant with permission to bind and publish can craft pathological selectors that cause excessive CPU consumption in the broker scheduler, leading to denial of service conditions. This impacts availability but does not indicate confidentiality or integrity compromise.
Mitigation Recommendations
This vulnerability is fixed in rabbitmq-server versions 4.0.23, 4.1.14, 4.2.9, and 4.3.3. Users should upgrade to these or later versions to remediate the issue. No vendor advisory content contradicts this; therefore, upgrading is the recommended mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-29T15:02:20.412Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab6a5d5f7a7c54106055645
Added to database: 09/25/2026, 16:48:21 UTC
Last enriched: 09/25/2026, 17:03:19 UTC
Last updated: 09/25/2026, 17:07:40 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.