Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-67238
Authenticated AMQP clients can exhaust the RabbitMQ atom table through reply-to queue names
Technology
RabbitMQ
CVSS Score
7.1 / 10.0
Affected Versions
4.2.0 to 4.2.6; 4.3.0
Upstream Fix
4.2.7 and 4.3.1 (public)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
Queue names and routing keys beginning amq.rabbitmq.reply-to. are decoded in a way that creates an Erlang atom from a client-supplied node name before the name is checked. Atoms are never garbage collected, so any authenticated AMQP 0-9-1 client can crash the whole Erlang VM, with every vhost and connection on it, using about a million cheap requests.
Is your RabbitMQ deployment affected?
If you're running 4.2.0 to 4.2.6; 4.3.0, you need this patch. Book a discovery call to get covered.