PT-2026-98902 · Vmware · Rabbitmq

CVE-2026-66073

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.14 RabbitMQ versions 4.0.x through 4.0.19 RabbitMQ versions 4.1.x through 4.1.10 RabbitMQ versions 4.2.x through 4.2.5
Description An atom table exhaustion issue exists in the management API. The PUT /api/queues/:vhost/:name endpoint, as well as the exchanges and bindings endpoints, accepts a node JSON field. The value of this field is processed through rabbitnodes:make and listtoatom without a prior cluster membership check, causing each unique value to permanently leak one atom. This can be triggered by any user with the management tag and access to at least one vhost. Approximately 900,000 requests can crash the virtual machine via the system limit, resulting in service loss for all tenants. The issue originates from the getnode/1 function in rabbitmgmtutil.erl, which is the primary vector used by directrequest/6.
Recommendations Update RabbitMQ to version 3.13.15. Update RabbitMQ to version 4.0.20. Update RabbitMQ to version 4.1.11. Update RabbitMQ to version 4.2.6.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66073
GHSA-6V53-R759-JRVX

Affected Products

Rabbitmq