Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: rabbitmq-server4.3: * rabbitmq-server4.3-4.3.4-0.2.hum1 (aarch64, x86_64) * rabbitmq-server4.3-4.3.4-0.2.hum1.src (src) Security Fix(es): rabbitmq-server4.3: * CVE-2026-59248 * CVE-2026-65624
AI Analysis
Technical Summary
CVE-2026-59248 is a denial of service vulnerability in cowlib, an HTTP parser library used by RabbitMQ components included in Red Hat Hardened Images. The flaw allows an unauthenticated remote attacker to send specially crafted HTTP/2 or HTTP/3 frames containing oversized HPACK or QPACK prefixed integers. This triggers an unbounded decoding process that causes excessive memory allocation and garbage collection, leading to memory exhaustion and service outage. The vulnerability is tracked under CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has released an advisory (RHSA-2026:47231) describing the issue and affected RPM versions (rabbitmq-server4.3-4.3.4-0.2.hum1 for aarch64 and x86_64). Currently, no patch or mitigation meeting Red Hat's standards is available.
Potential Impact
The vulnerability allows unauthenticated remote attackers to cause a denial of service by exhausting memory resources on affected systems running vulnerable versions of rabbitmq-server4.3. This can result in service outages due to excessive memory consumption and garbage collection triggered by malformed HTTP/2 or HTTP/3 frames. There is no impact on confidentiality or integrity reported. The attack vector is network-based and requires no privileges or user interaction.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for future updates or fixes. Applying the provided security update when available is recommended. Until a fix is released, consider limiting exposure of affected services to untrusted networks if possible.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: rabbitmq-server4.3: * rabbitmq-server4.3-4.3.4-0.2.hum1 (aarch64, x86_64) * rabbitmq-server4.3-4.3.4-0.2.hum1.src (src) Security Fix(es): rabbitmq-server4.3: * CVE-2026-59248 * CVE-2026-65624
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59248 is a denial of service vulnerability in cowlib, an HTTP parser library used by RabbitMQ components included in Red Hat Hardened Images. The flaw allows an unauthenticated remote attacker to send specially crafted HTTP/2 or HTTP/3 frames containing oversized HPACK or QPACK prefixed integers. This triggers an unbounded decoding process that causes excessive memory allocation and garbage collection, leading to memory exhaustion and service outage. The vulnerability is tracked under CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has released an advisory (RHSA-2026:47231) describing the issue and affected RPM versions (rabbitmq-server4.3-4.3.4-0.2.hum1 for aarch64 and x86_64). Currently, no patch or mitigation meeting Red Hat's standards is available.
Potential Impact
The vulnerability allows unauthenticated remote attackers to cause a denial of service by exhausting memory resources on affected systems running vulnerable versions of rabbitmq-server4.3. This can result in service outages due to excessive memory consumption and garbage collection triggered by malformed HTTP/2 or HTTP/3 frames. There is no impact on confidentiality or integrity reported. The attack vector is network-based and requires no privileges or user interaction.
Mitigation Recommendations
Red Hat currently states that no mitigation is available or that existing options do not meet their criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for future updates or fixes. Applying the provided security update when available is recommended. Until a fix is released, consider limiting exposure of affected services to untrusted networks if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47231
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-65624"]
- State
- PUBLISHED
Threat ID: 6a6940089c2644c7f866596b
Added to database: 07/28/2026, 23:49:28 UTC
Last enriched: 08/16/2026, 17:43:21 UTC
Last updated: 09/12/2026, 22:01:35 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.