Erlang VM Atom Consumption in RabbitMQ Messaging and Streaming Broker
CVE-2026-67222

5.9MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67222?

A vulnerability in RabbitMQ impacts versions 3.13.0 to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, where the handling of colon-delimited tokens in an attacker-controlled auth_mechanism value can lead to the permanent consumption of Erlang VM atoms. This flaw may facilitate a node crash when a large request is made, especially when using Shovel or Federation plugins, and requires the policymaker tag to set auth_mechanism. The issue has been resolved in subsequent releases.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.