PT-2026-98902 · Vmware · Rabbitmq
CVE-2026-66073
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 3.13.0 through 3.13.14
RabbitMQ versions 4.0.x through 4.0.19
RabbitMQ versions 4.1.x through 4.1.10
RabbitMQ versions 4.2.x through 4.2.5
Description
An atom table exhaustion issue exists in the management API. The
PUT /api/queues/:vhost/:name endpoint, as well as the exchanges and bindings endpoints, accepts a node JSON field. The value of this field is processed through rabbitnodes:make and listtoatom without a prior cluster membership check, causing each unique value to permanently leak one atom. This can be triggered by any user with the management tag and access to at least one vhost. Approximately 900,000 requests can crash the virtual machine via the system limit, resulting in service loss for all tenants. The issue originates from the getnode/1 function in rabbitmgmtutil.erl, which is the primary vector used by directrequest/6.Recommendations
Update RabbitMQ to version 3.13.15.
Update RabbitMQ to version 4.0.20.
Update RabbitMQ to version 4.1.11.
Update RabbitMQ to version 4.2.6.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq