live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

RabbitMQ 4.3 hardened image update closes two unauthenticated denial-of-service paths

Red Hat’s August 21 build fixes HTTP/1.1, HTTP/2 and HTTP/3 parsing flaws that can exhaust memory without authentication.

RabbitMQ hardened image security update: old parser flaws replaced by a fixed build.
AI-generated illustration
By The News Desk· Aug 23, 2026

Red Hat has issued an Important security update for the RabbitMQ 4.3 RPM in Red Hat Hardened Images. The August 21 advisory ships rabbitmq-server4.3-4.3.5-0.1.hum1 for x86_64 and aarch64 and addresses two remotely exploitable denial-of-service flaws.

What changed

The update covers CVE-2026-59248 and CVE-2026-65624. Red Hat rates both vulnerabilities Important with CVSS 3.1 base scores of 7.5. Each can be reached over the network without privileges or user interaction, and each can exhaust memory until the affected service becomes unavailable.

CVE-2026-59248 is in Cowlib’s HTTP parser. Specially crafted HTTP/2 or HTTP/3 frames can carry oversized HPACK or QPACK prefixed integers, triggering unbounded decoding, memory allocation and garbage collection. Red Hat says the result can be memory exhaustion on either a vulnerable server or client.

CVE-2026-65624 affects Cowboy’s handling of HTTP/1.1 headers. An attacker can submit repeated header lines with the same name to bypass the max_headers limit. Concatenating those values can then grow the connection process until the Erlang virtual machine runs out of memory.

Who is affected

The August 21 advisory applies specifically to the rabbitmq-server4-3-main component in Red Hat Hardened Images. Red Hat’s CVE records also show earlier fixes for RabbitMQ 4.2 and 4.3 hardened-image streams issued on July 28; the newer advisory supplies the listed RabbitMQ 4.3 build.

Both attack paths are remote and unauthenticated. Their impact is availability rather than confidentiality or integrity, but the absence of an authentication requirement lowers the barrier to triggering a service outage when a vulnerable endpoint is reachable.

What to do

Red Hat lists both issues as fixed by RHSA-2026:57882 and does not provide a mitigation that meets its deployment and stability criteria. Operators using the RabbitMQ 4.3 hardened image should identify deployments based on an older build and apply the updated image through Red Hat’s hardened-images service.

After rollout, teams should confirm that workloads resolve to the corrected 4.3.5-0.1.hum1 RPM build for their architecture. Because both flaws consume memory through malformed HTTP input, monitoring for abnormal RabbitMQ or Erlang memory growth can also help identify attempted exploitation while updates are being deployed.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.