RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service
Published Sep 25, 2026
5.9
MEDIUMCVSS 4.0
EPSS 0.35%
Description
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacker-controlled runtime parameter values into non-garbage-collected Erlang atoms before bounding them or checking a fixed allowlist. Exploitation requires network access to the Management HTTP API, valid credentials with both the management and policymaker tags, permission to set Shovel runtime parameters on a vhost, and the rabbitmq_shovel and rabbitmq_shovel_management plugins to be enabled. The attacker can exhaust the node-wide atom table and deny service, and malicious parameters are stored durably and reparsed when workers start, so atom pressure can recur after restart without a live attacker connection. This issue is fixed in versions 4.2.9 and 4.3.3.
Affected products
-
- Version >= 4.2.0, < 4.2.9StatusaffectedConstraints-
- Version >= 4.3.0, < 4.3.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rabbitmq | Rabbitmq-Server | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87225 Advisory
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.3 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-8mpg-qw9r-m5cr exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87225 | Advisory | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.3 | x_refsource_MISC | |
| https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-8mpg-qw9r-m5cr | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.