Impact
The vulnerability allows an authenticated tenant to open stream connections through port 5552 that skip the per-vhost and per-user connection‑limit checks in the stream protocol. As a result, the tenant can exceed the operator‑enforced caps, potentially exhausting broker resources and affecting other tenants. The flaw is a classic resource exhaustion and isolation breach (CWE-770).
Affected Systems
RabbitMQ Server, versions prior to 4.2.7 and 4.3.1. Any deployment with the rabbitmq_stream plugin enabled and operator‑configured per‑user/per‑vhost limits is affected.
Risk and Exploitability
The CVSS score is 6, indicating a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation. The likely attack vector is an authenticated user connecting via the stream protocol on port 5552, leveraging normal credentials and bypassing normal throttling mechanisms.
OpenCVE Enrichment