Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v53-r759-jrvx

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью

Описание

Atom table exhaustion via management API node field

Origin

This vulnerability was identified by Team RabbitMQ and/or other teams at Broadcom, not via a responsible disclosure from an external researcher.

Impact

Roughly 900K requests crash the VM via system_limit, and all tenants lose service. The crash takes between 30 minutes and 2.5 hours over keep-alive. The management tag is routinely given to application teams, monitoring tools, and similar consumers, so this is a low-privilege remote denial of service.

Description

PUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts a node JSON field. The value goes through rabbit_nodes:make → list_to_atom with no cluster membership check first. Each unique value permanently leaks one atom.

A March 2026 refactoring (ea61ce2563) introduced safe helpers in rabbit_mgmt_nodes.erl (parse_node_name, safe_atom, and require_node_name, using binary_to_existing_atom) and fixed several callers (QQ replica ops, wm_auth_attempts, wm_node_memory_ets, get_sort_reverse, and rabbit_federation_mgmt), but get_node/1 in rabbit_mgmt_util.erl:880-885, the primary vector used by direct_request/6, was not migrated.

Preconditions

Any user with the management tag and one vhost, the lowest privilege level.

CVSS

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N (6.0, Moderate). Fixed in 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0.

Пакеты

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.13.0, < 3.13.15

3.13.15

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.20

4.0.20

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.11

4.1.11

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.6

4.2.6

EPSS

Процентиль: 24%
0.00331
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts a node JSON field. The value goes through rabbitnodes:make → listtoatom with no cluster membership check first. Each unique value permanently leaks one atom. A March 2026 refactoring (ea61ce2563) introduced safe helpers in rabbitmgmtnodes.erl (parsenodename, safeatom, and requirenodename, using binarytoexistingatom) and fixed several callers (QQ replica ops, wmauthattempts, wmnodememoryets, getsortreverse, and rabbitfederationmgmt), but getnode/1 in rabbitmgmtutil.erl:880-885, the primary vector used by directrequest/6, was not Roughly 900K requests crash the VM via systemlimit, and all tenants lose Any user with the management tag and one vhost, the lowest privilege This issue is fixed in versions 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6.

nvd
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts a node JSON field. The value goes through rabbitnodes:make → listtoatom with no cluster membership check first. Each unique value permanently leaks one atom. A March 2026 refactoring (ea61ce2563) introduced safe helpers in rabbitmgmtnodes.erl (parsenodename, safeatom, and requirenodename, using binarytoexistingatom) and fixed several callers (QQ replica ops, wmauthattempts, wmnodememoryets, getsortreverse, and rabbitfederationmgmt), but getnode/1 in rabbitmgmtutil.erl:880-885, the primary vector used by directrequest/6, was not Roughly 900K requests crash the VM via systemlimit, and all tenants lose Any user with the management tag and one vhost, the lowest privilege This issue is fixed in versions 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6.

msrc
2 дня назад

RabbitMQ: Atom table exhaustion via management API node field

debian
8 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...

EPSS

Процентиль: 24%
0.00331
Низкий

Дефекты

CWE-400