PT-2026-97566 · Vmware · Rabbitmq

CVE-2026-67238

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.2.7 RabbitMQ versions prior to 4.3.1
Description An authenticated AMQP 0-9-1 client can crash the Erlang VM, affecting all vhosts and connections, by sending approximately 1 million requests. The issue occurs when rabbit pid codec:decompose from binary/1 parses a caller-supplied ETF-encoded binary and calls binary to atom(Node, utf8) on the node-name field. This process is triggered via rabbit volatile queue:pid from name/2 for any queue name or routing key starting with amq.rabbitmq.reply-to. Because the membership check for CandidateNodes occurs after the atom is created and atoms are not garbage collected, the system can be exhausted. This requires an authenticated connection and the absence of strict per-connection rate limits.
Recommendations Update to version 4.2.7. Update to version 4.3.1.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67238
GHSA-X96J-244M-MRR2

Affected Products

Rabbitmq