Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67238

Authenticated AMQP clients can exhaust the RabbitMQ atom table through reply-to queue names

Technology

RabbitMQ

CVSS Score

7.1 / 10.0

Affected Versions

4.2.0 to 4.2.6; 4.3.0

Upstream Fix

4.2.7 and 4.3.1 (public)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

Queue names and routing keys beginning amq.rabbitmq.reply-to. are decoded in a way that creates an Erlang atom from a client-supplied node name before the name is checked. Atoms are never garbage collected, so any authenticated AMQP 0-9-1 client can crash the whole Erlang VM, with every vhost and connection on it, using about a million cheap requests.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.2.0 to 4.2.6; 4.3.0, you need this patch. Book a discovery call to get covered.