PT-2026-97581 · Vmware · Rabbitmq

CVE-2026-67228

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.2.7 RabbitMQ versions prior to 4.3.1
Description The runtime-parameters lookup path coerces the URL :component segment to an atom using the rabbit data coercion:to atom/1 function within lookup component() (deps/rabbit/src/rabbit runtime parameters.erl). This process creates a new atom for any previously unseen value. Since the Erlang atom table is bounded and atoms are not garbage collected, an authorized policymaker can exhaust the atom table by issuing approximately one million requests with distinct component values, causing the node to crash and resulting in a denial of service.
Recommendations Update to version 4.2.7. Update to version 4.3.1.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67228
GHSA-73QP-FWH4-2Q5G

Affected Products

Rabbitmq