RabbitMQ: Atom table exhaustion via management API node field
Published Sep 25, 2026
6.0
MEDIUMCVSS 4.0
EPSS 0.33%
Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts a node JSON field. The value goes through rabbitnodes:make → listtoatom with no cluster membership check first. Each unique value permanently leaks one atom. A March 2026 refactoring (ea61ce2563) introduced safe helpers in rabbitmgmtnodes.erl (parsenodename, safeatom, and requirenodename, using binarytoexistingatom) and fixed several callers (QQ replica ops, wmauthattempts, wmnodememoryets, getsortreverse, and rabbitfederationmgmt), but getnode/1 in rabbitmgmtutil.erl:880-885, the primary vector used by directrequest/6, was not Roughly 900K requests crash the VM via systemlimit, and all tenants lose Any user with the management tag and one vhost, the lowest privilege This issue is fixed in versions 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6.
Affected products
-
Affected
- ≥ 3.13.0, < 3.13.15
- ≥ 4.0.0, < 4.0.20
- ≥ 4.1.0, < 4.1.11
- ≥ 4.2.0, < 4.2.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rabbitmq | Rabbitmq-Server | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87149 Advisory
- https://github.com/rabbitmq/rabbitmq-server/commit/7f64311471840e68f8cae09e4d4fdc4c8aca9229 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6v53-r759-jrvx x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87149 | Advisory | |
| https://github.com/rabbitmq/rabbitmq-server/commit/7f64311471840e68f8cae09e4d4fdc4c8aca9229 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6v53-r759-jrvx | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data