RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.
Conclusion & alert: CVE-2023-46118 is rated Moderate Risk (41.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.08%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.28% | 1.08% | +0.80% |
| 2 | 2026-03-22 | 0.20% | 0.28% | +0.08% |
| 3 | 2025-11-21 | — | 0.20% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.9 | 3.1 | MEDIUM |
|
1.2 | 3.6 | [email protected] |
| 4.9 | 3.1 | MEDIUM |
|
1.2 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-46118 not yet assigned priority: Debian including 1 source packages (rabbitmq-server), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2023-46118 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-46118 |
suse
|
medium | CVE-2023-46118 severity moderate: SUSE including 32 source package names (elixir115-1.15.7-150300.7.5.1, elixir115-doc-1.15.7-150300.7.5.1, …), 89 product×package rows across 14 product lines (HPE Helion OpenStack 8, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP7, … (14 product lines)): Fixed 79, Will Not Fix 10. | https://www.suse.com/security/cve/CVE-2023-46118/ |
ubuntu
|
medium | CVE-2023-46118 medium priority: Ubuntu including 1 source packages (rabbitmq-server), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 9, needs-triage 2, ignored 1. | https://ubuntu.com/security/CVE-2023-46118 |