PT-2026-105058 · Azure Linux · Rabbitmq-Server

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The runtime-parameters lookup path coerces the URL :component segment to an atom with rabbit data coercion:to atom/1 in lookup component/1 (deps/rabbit/src/rabbit runtime parameters.erl), creating a new atom for any previously unseen value. A safe helper, rabbit registry:binary to type/1, which uses binary to existing atom with a catch, already exists but is not used at this call site. lookup component/1 calls rabbit data coercion:to atom(Component) on the :component segment of the request URL, converting an attacker-supplied string into a new atom. Because the Erlang atom table is bounded and atoms are never garbage collected, an authorized policymaker issuing roughly one million requests with distinct component values can exhaust the atom table and crash the node, resulting in a denial of service. Preconditions include Exploitation requires policymaker privileges and roughly one million requests.. This issue is fixed in versions 4.2.7 and 4.3.1.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-105777

Affected Products

Rabbitmq-Server