PT-2026-97566 · Vmware · Rabbitmq
CVE-2026-67238
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 4.2.7
RabbitMQ versions prior to 4.3.1
Description
An authenticated AMQP 0-9-1 client can crash the Erlang VM, affecting all vhosts and connections, by sending approximately 1 million requests. The issue occurs when
rabbit pid codec:decompose from binary/1 parses a caller-supplied ETF-encoded binary and calls binary to atom(Node, utf8) on the node-name field. This process is triggered via rabbit volatile queue:pid from name/2 for any queue name or routing key starting with amq.rabbitmq.reply-to. Because the membership check for CandidateNodes occurs after the atom is created and atoms are not garbage collected, the system can be exhausted. This requires an authenticated connection and the absence of strict per-connection rate limits.Recommendations
Update to version 4.2.7.
Update to version 4.3.1.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq