PT-2026-97582 · Vmware · Rabbitmq
CVE-2026-67229
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.0
Description
An administrator with the required tags can crash the node in a single request by importing a crafted definitions file. The issue occurs because the
add vhost/2 function calls rabbit data coercion:atomize keys/1, which uses an unsafe binary to atom variant on the vhost metadata map. A vhosts entry containing approximately 1 million unique metadata keys can exhaust the atom table during the import process.Recommendations
Update to version 3.13.15
Update to version 4.0.20
Update to version 4.1.11
Update to version 4.2.6
Update to version 4.3.0
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq