Database/Control plane, storage & DevOps
RabbitMQ: HTTP API enforces no request body limit
CVSS 4.9CVE-2023-46118Control plane, storage & DevOpscurated
Impact
HTTP API enforces no request body limit -> authenticated user exhausts node memory (DoS)
Who can reach it
Network (remote)
What to do
Control-plane: broker upgrade; set max_message_size
References
Related entries
- RabbitMQ: Unsanitized username rendered in the management UICVE-2021-32718 · RabbitMQLow
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passCVE-2024-23444 · ElasticsearchMedium
- Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttling: A race between AMD PMU enablementCVE-2022-49781 · Linux perf/x86/amd - race between amd_pmu_enable_all, perf NMI and throttlingMedium
- Intel Neural Compressor (TOCTOU): A time-of-check/time-of-use race in Neural Compressor lets an authenticated localCVE-2024-21792 · Intel Neural Compressor (TOCTOU)Medium
- GitLab: stored XSS via pasted HTML in the Content EditorCVE-2026-19619 · GitLab CE/EE (Content Editor, pasted HTML sanitization)Medium
- Rittal CMC III cabinet lock / access-card system: The access cards used to open control cabinets secured with RittalCVE-2022-40633 · Rittal CMC III cabinet lock / access-card systemMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.