PT-2026-105170 · Bitnami · Rabbitmq

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied list to atom/1 to every colon-delimited token in an attacker-controlled auth mechanism value, permanently consuming Erlang VM atoms and allowing the node to be crashed with a large request. Exploitation requires the Shovel or Federation plugin to be in use, and setting auth mechanism requires the policymaker tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-RABBITMQ-2026-67222

Affected Products

Rabbitmq