PT-2026-97582 · Vmware · Rabbitmq

CVE-2026-67229

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An administrator with the required tags can crash the node in a single request by importing a crafted definitions file. The issue occurs because the add vhost/2 function calls rabbit data coercion:atomize keys/1, which uses an unsafe binary to atom variant on the vhost metadata map. A vhosts entry containing approximately 1 million unique metadata keys can exhaust the atom table during the import process.
Recommendations Update to version 3.13.15 Update to version 4.0.20 Update to version 4.1.11 Update to version 4.2.6 Update to version 4.3.0

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67229
GHSA-GGRW-QM45-HWPV

Affected Products

Rabbitmq