Medium severity4.9NVD Advisory· Published Oct 25, 2023· Updated Jun 17, 2026
CVE-2023-46118
CVE-2023-46118
Description
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rabbit_commonHex | >= 3.12.0, < 3.12.7 | 3.12.7 |
rabbit_commonHex | >= 3.11.0, < 3.11.24 | 3.11.24 |
Affected products
14(expand)+ 1 more
- (no CPE)
- (no CPE)range: < 3.12.7
- osv-coords11 versionspkg:bitnami/rabbitmqpkg:rpm/opensuse/elixir115&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/erlang26&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/rabbitmq-server&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/rabbitmq-server&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/rabbitmq-server313&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/elixir115&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/erlang26&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/rabbitmq-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4pkg:rpm/suse/rabbitmq-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5pkg:rpm/suse/rabbitmq-server313&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6
< 3.11.24+ 10 more
- (no CPE)range: < 3.11.24
- (no CPE)range: < 1.15.7-150300.7.5.1
- (no CPE)range: < 26.2.1-150300.7.5.1
- (no CPE)range: < 3.8.11-150300.3.14.1
- (no CPE)range: < 3.8.11-150300.3.14.1
- (no CPE)range: < 3.13.1-150600.13.5.3
- (no CPE)range: < 1.15.7-150300.7.5.1
- (no CPE)range: < 26.2.1-150300.7.5.1
- (no CPE)range: < 3.8.11-150300.3.14.1
- (no CPE)range: < 3.8.11-150300.3.14.1
- (no CPE)range: < 3.13.1-150600.13.5.3
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-w6cq-9cf4-gqpgghsaADVISORY
- github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-w6cq-9cf4-gqpgnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-46118ghsaADVISORY
- lists.debian.org/debian-lts-announce/2023/12/msg00009.htmlnvdWEB
- www.debian.org/security/2023/dsa-5571nvdWEB
News mentions
0No linked articles in our index yet.