PT-2026-98923 · Vmware · Rabbitmq

CVE-2026-67415

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description The Shovel parameter parser converts attacker-controlled runtime parameter values into non-garbage-collected Erlang atoms before bounding them or checking a fixed allowlist. Erlang atoms are constants whose names cannot be changed and are not reclaimed by the garbage collector. An attacker with network access to the Management HTTP API, valid credentials with management and policymaker tags, permission to set Shovel runtime parameters on a vhost, and the rabbitmq shovel and rabbitmq shovel management plugins enabled can exhaust the node-wide atom table. This leads to a denial of service. Because malicious parameters are stored durably and reparsed when workers start, the atom pressure can recur after a restart even without an active attacker connection.
Recommendations Update to version 4.2.9. Update to version 4.3.3.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67415
GHSA-8MPG-QW9R-M5CR

Affected Products

Rabbitmq