CVE-2026-67229Medium· 6.9▾ SunlitRabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on the vhost metadata map. The 20 …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 38 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on the vhost metadata map. The 20 MB management body limit fits ~1M+ short keys. Admin-only. An administrator importing a crafted definitions file can crash the node in a single request: a vhosts entry with ~1M unique metadata keys exhausts the atom table during import. Preconditions include administrator tag. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67405Medium· 5.3RabbitMQ is a messaging and streaming broker
CVE-2026-67232High· 8.2RabbitMQ is a messaging and streaming broker
CVE-2026-67235High· 7.1RabbitMQ is a messaging and streaming broker
CVE-2026-67231Critical· 9.1RabbitMQ is a messaging and streaming broker
CVE-2026-67219Medium· 6.0RabbitMQ is a messaging and streaming broker
CVE-2026-66074Medium· 6.0RabbitMQ is a messaging and streaming broker