Admin-Only Vulnerabilities in RabbitMQ Messaging Broker
CVE-2026-67226

6.9MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67226?

The RabbitMQ messaging broker is vulnerable to an admin-only atom exhaustion attack. This issue allows an administrator to create a user or import definitions with an excessive number of unique tags, potentially leading to node crashes. Specifically, an administrator can trigger a crash by sending a single request that exceeds the 20 MB body limit with approximately 1 million unique tag strings. The affected versions of RabbitMQ range from 4.0.0 to 4.0.22, along with 4.1.14 and 4.2.7. The vulnerability has been addressed in the latest updates, ensuring enhanced stability and security.

Affected Version(s)

rabbitmq-server >= 4.0.0, < 4.0.22 < 4.0.0, 4.0.22

rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14

rabbitmq-server >= 4.2.0, < 4.2.7 < 4.2.0, 4.2.7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.