CVE-2026-67226Medium· 6.9▾ SunlitRabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB management …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB management body limit fits ~3-4M short tag strings. An administrator can crash the node in a single request by creating a user (or importing definitions) with ~1M unique tag administrator. This issue is fixed in versions 4.0.22 and 4.1.14 and 4.2.7.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67227Medium· 5.9RabbitMQ is a messaging and streaming broker
CVE-2026-67228Medium· 6.9RabbitMQ is a messaging and streaming broker
CVE-2026-67238High· 7.1RabbitMQ is a messaging and streaming broker
CVE-2026-67222Medium· 5.9RabbitMQ is a messaging and streaming broker
CVE-2026-66071Medium· 6.0RabbitMQ is a messaging and streaming broker
CVE-2026-67415Medium· 5.9RabbitMQ is a messaging and streaming broker