CVE-2026-67227

Summary

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: toatom on global-parameter :name. resourceexists/2 (and the PUT/DELETE handlers) call rabbitdatacoercion:toatom/1 on the :name URL path segment. toatom/1 uses binarytoatom/2 (unsafe). The endpoint requires policymaker (not management, but below A user with the policymaker tag can crash the node by exhausting the atom table via repeated requests to /api/global-parameters/:name with unique :name Management plugin enabled policymaker tag ~1M HTTP. This issue is fixed in versions 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1.

Affected Software

VendorProductVersion RangeStatus
rabbitmqrabbitmq-server>= 4.0.0, < 4.0.22affected
rabbitmqrabbitmq-server>= 4.1.0, < 4.1.14affected
rabbitmqrabbitmq-server>= 4.2.0, < 4.2.7affected
rabbitmqrabbitmq-server>= 4.3.0, < 4.3.1affected

Weaknesses

  • CWE-400: CWE-400: Uncontrolled Resource Consumption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References