PT-2026-98904 · Vmware · Rabbitmq

CVE-2026-67222

·

Published

2026-09-25

·

Updated

2026-09-28

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.14 RabbitMQ versions 4.0.x prior to 4.0.20 RabbitMQ versions 4.1.x prior to 4.1.11 RabbitMQ versions 4.2.x prior to 4.2.6
Description An issue exists where the mechanisms/1 function applies list to atom/1 to every colon-delimited token within an attacker-controlled auth mechanism value. This leads to the permanent consumption of Erlang VM atoms, which can cause the node to crash when processing a large request. Exploitation of this issue requires the Shovel or Federation plugin to be active and the user to possess the policymaker tag to set the auth mechanism value.
Recommendations Update RabbitMQ to version 3.13.15. Update RabbitMQ to version 4.0.20. Update RabbitMQ to version 4.1.11. Update RabbitMQ to version 4.2.6.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67222
GHSA-85JR-6RR2-J73R

Affected Products

Rabbitmq