Admin-Only Vulnerabilities in RabbitMQ Messaging Broker
CVE-2026-67226
6.9MEDIUM
What is CVE-2026-67226?
The RabbitMQ messaging broker is vulnerable to an admin-only atom exhaustion attack. This issue allows an administrator to create a user or import definitions with an excessive number of unique tags, potentially leading to node crashes. Specifically, an administrator can trigger a crash by sending a single request that exceeds the 20 MB body limit with approximately 1 million unique tag strings. The affected versions of RabbitMQ range from 4.0.0 to 4.0.22, along with 4.1.14 and 4.2.7. The vulnerability has been addressed in the latest updates, ensuring enhanced stability and security.
Affected Version(s)
rabbitmq-server >= 4.0.0, < 4.0.22 < 4.0.0, 4.0.22
rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14
rabbitmq-server >= 4.2.0, < 4.2.7 < 4.2.0, 4.2.7
