PT-2026-97564 · Vmware+1 · Rabbitmq+1

CVE-2026-67220

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An authenticated low-privilege AMQP user can cause a cross-tenant Denial of Service (DoS) by crashing the entire broker node. This occurs when a binding is created on an x-jms-topic exchange, where the add binding/3 function processes the rjms erlang selector argument using erl scan:string/1 and erl parse:parse term/1. Because erl scan:string/1 interns every atom literal it tokenizes and the validate binding/2 function does not perform any validation or enforce a length cap, a raw AMQP client can send arbitrary selector strings to exhaust resources. This issue requires the rabbitmq jms topic exchange plugin to be enabled and the user to have read permissions on an x-jms-topic exchange and write permissions on a queue.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.0. As a temporary mitigation, disable the rabbitmq jms topic exchange plugin if it is not required for the deployment.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67220
GHSA-R3QR-4H63-MVJ2

Affected Products

Rabbitmq
Rabbitmq Jms Topic Exchange