PT-2026-98908 · Vmware · Rabbitmq
CVE-2026-67227
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.0.0 through 4.0.21
RabbitMQ versions 4.1.x prior to 4.1.14
RabbitMQ versions 4.2.x prior to 4.2.7
RabbitMQ versions 4.3.x prior to 4.3.1
Description
An atom exhaustion issue exists when the Management plugin is enabled. A user with the
policymaker tag can crash the node by sending repeated HTTP requests with unique values in the :name URL path segment to the /api/global-parameters/:name endpoint. This occurs because the resourceexists/2 function and the PUT/DELETE handlers call rabbitdatacoercion:toatom/1, which utilizes the unsafe binarytoatom/2 function, leading to the exhaustion of the atom table.Recommendations
Update to version 4.0.22
Update to version 4.1.14
Update to version 4.2.7
Update to version 4.3.1
Restrict access to the
/api/global-parameters/:name endpoint for users with the policymaker tag as a temporary mitigation.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq