Loading HuntDB...

GHSA-hrfh-7j5f-8ccr

GitHub Security Advisory

Pivotal RabbitMQ is vulnerable to a denial of service attack

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

Affected Packages

Hex RabbitMQ
Affected versions: 3.7.0 (fixed in 3.7.21)
Hex RabbitMQ
Affected versions: 3.8.0 (fixed in 3.8.1)
Hex RabbitMQ
Affected versions: 0 (fixed in 1.16.7)
Hex RabbitMQ
Affected versions: 1.17.0 (fixed in 1.17.4)

Related CVEs

Key Information

GHSA ID
GHSA-hrfh-7j5f-8ccr
Published
May 24, 2022 5:01 PM
Last Modified
April 2, 2025 11:10 PM
CVSS Score
7.5 /10
Primary Ecosystem
Hex
Primary Package
RabbitMQ
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 3, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.