USN-8869-1: RabbitMQ Server flaw, denial of service risk via HTTP/2
Ubuntu fixes a flaw in RabbitMQ Server (CVE-2026-59248) that allows denial of service via malformed HTTP/2 headers. A service restart is required.
UptimeMag editorial team · 6 October 2026 · 1 min read

Ubuntu has published security notice USN-8869-1, dated 6 October 2026, for a vulnerability in RabbitMQ Server that can lead to a remote denial of service. It affects anyone running RabbitMQ-based message queues on Ubuntu infrastructure, from production brokers to microservice integration systems.
The problem
According to the official Ubuntu advisory, RabbitMQ Server mishandles certain HTTP/2 headers. An attacker can exploit this bug by sending specially crafted network traffic, causing memory exhaustion and a crash of the service. The flaw is tracked as CVE-2026-59248.
Affected packages and fixed versions
The package affected is rabbitmq-server (an AMQP server written in Erlang). The versions that fix the issue, according to the Ubuntu advisory, are:
| Ubuntu Release | Codename | Fixed version |
|---|---|---|
| 26.04 LTS | Resolute | 4.0.5-10ubuntu5.1 |
| 24.04 LTS | Noble | 3.12.1-1ubuntu1.6 |
| 22.04 LTS | Jammy | 3.9.27-0ubuntu0.5 |
| 20.04 LTS | Focal | 3.8.3-0ubuntu0.3+esm1 |
For Ubuntu 20.04 LTS the fix is only available through Ubuntu Pro (ESM), as noted in the advisory.
What to do
After the standard system update (apt update && apt upgrade), the Ubuntu advisory specifies that RabbitMQ Server must be restarted to apply the changes:
sudo systemctl restart rabbitmq-server
Those running RabbitMQ in a cluster should plan the restart node by node to avoid service interruptions, checking cluster status with rabbitmqctl cluster_status before and after the operation.
The full advisory, with CVE references, is available on the official Ubuntu Security Notices website at USN-8869-1.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.