PT-2026-98907 · Vmware · Rabbitmq

CVE-2026-67226

·

Published

2026-09-25

·

Updated

2026-10-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.0.0 through 4.0.21 RabbitMQ versions 4.1.x prior to 4.1.14 RabbitMQ versions 4.2.x prior to 4.2.7
Description An administrator can cause a node crash via a single request by creating a user or importing definitions containing approximately 1 million unique tags. This occurs because the settags/2 function maps rabbitdatacoercion:toatom/1 over the user's tags list at the 'PUT /api/users' endpoint, leading to atom exhaustion. Atom exhaustion is a condition where the system runs out of unique atoms, which are immutable symbols used by the Erlang runtime, causing the application to terminate.
Recommendations Update RabbitMQ to version 4.0.22. Update RabbitMQ to version 4.1.14. Update RabbitMQ to version 4.2.7.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105765
BIT-RABBITMQ-2026-67226
CVE-2026-67226
GHSA-34C7-R8W9-5WV8

Affected Products

Rabbitmq