Bug 2539723 (CVE-2026-67238) - CVE-2026-67238 rabbitmq-server: RabbitMQ: Denial of Service due to atom-table exhaustion via reply-to queue name decoding
Summary: CVE-2026-67238 rabbitmq-server: RabbitMQ: Denial of Service due to atom-table...
Keywords:
Status: NEW
Alias: CVE-2026-67238
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2540101
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-23 20:12 UTC by OSIDB Bzimport
Modified: 2026-09-24 14:08 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-23 20:12:25 UTC
RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, utf8) on the node-name field. It is reached from rabbit_volatile_queue:pid_from_name/2, which is invoked for any queue name / routing key beginning amq.rabbitmq.reply-to.. The CandidateNodes membership check happens after the atom is created, and the surrounding try/catch cannot reclaim atoms (they are never GC'd). binary_to_existing_atom is not used. Any authenticated AMQP client can crash the entire Erlang VM (all vhosts, all connections) with ~1M cheap requests. Preconditions include Authenticated AMQP 0-9-1 connection to any vhost No per-connection rate limit low enough to make ~1M operations infeasible. This issue is fixed in versions 4.2.7 and 4.3.1.


Note You need to log in before you can comment on or make changes to this bug.