Erlang VM Atom Consumption in RabbitMQ Messaging and Streaming Broker
CVE-2026-67222
5.9MEDIUM
What is CVE-2026-67222?
A vulnerability in RabbitMQ impacts versions 3.13.0 to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, where the handling of colon-delimited tokens in an attacker-controlled auth_mechanism value can lead to the permanent consumption of Erlang VM atoms. This flaw may facilitate a node crash when a large request is made, especially when using Shovel or Federation plugins, and requires the policymaker tag to set auth_mechanism. The issue has been resolved in subsequent releases.
Affected Version(s)
rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15
rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20
rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11
