PT-2026-98908 · Vmware · Rabbitmq

CVE-2026-67227

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.0.0 through 4.0.21 RabbitMQ versions 4.1.x prior to 4.1.14 RabbitMQ versions 4.2.x prior to 4.2.7 RabbitMQ versions 4.3.x prior to 4.3.1
Description An atom exhaustion issue exists when the Management plugin is enabled. A user with the policymaker tag can crash the node by sending repeated HTTP requests with unique values in the :name URL path segment to the /api/global-parameters/:name endpoint. This occurs because the resourceexists/2 function and the PUT/DELETE handlers call rabbitdatacoercion:toatom/1, which utilizes the unsafe binarytoatom/2 function, leading to the exhaustion of the atom table.
Recommendations Update to version 4.0.22 Update to version 4.1.14 Update to version 4.2.7 Update to version 4.3.1 Restrict access to the /api/global-parameters/:name endpoint for users with the policymaker tag as a temporary mitigation.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67227
GHSA-Q7X8-97RH-CR24

Affected Products

Rabbitmq