Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66071

Опубликовано: 25 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The token signature is verified first, so the attacker cannot forge scopes , but in IdP configurations where scope content is user-influenced, each login with a novel tag value leaks one In deployments where users can influence the scopes included in their IdP-issued JWT rabbitmqauthbackendoauth2 enabled IdP permits attacker-influenced scope values in signed tokens. This issue is fixed in versions 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1.

A flaw was found in rabbitmq-server where its OAuth2 authentication backend improperly converts token scope values into Erlang runtime atoms. In deployments where an Identity Provider (IdP) allows users to influence scope contents within their signed JSON Web Tokens (JWTs), an authenticated attacker can supply unique scope tags across multiple authentications. This gradually depletes the broker's non-garbage-collected atom table, ultimately crashing the broker and causing a denial of service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 16.2rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 17.1rabbitmq-serverOut of support scope
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2541515rabbitmq-server: rabbitmq-server: Denial of service via atom exhaustion in OAuth2 JWT scope parsing

EPSS

Процентиль: 25%
0.00342
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
9 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The token signature is verified first, so the attacker cannot forge scopes , but in IdP configurations where scope content is user-influenced, each login with a novel tag value leaks one In deployments where users can influence the scopes included in their IdP-issued JWT rabbitmqauthbackendoauth2 enabled IdP permits attacker-influenced scope values in signed tokens. This issue is fixed in versions 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1.

nvd
9 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The token signature is verified first, so the attacker cannot forge scopes , but in IdP configurations where scope content is user-influenced, each login with a novel tag value leaks one In deployments where users can influence the scopes included in their IdP-issued JWT rabbitmqauthbackendoauth2 enabled IdP permits attacker-influenced scope values in signed tokens. This issue is fixed in versions 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1.

msrc
4 дня назад

RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values

debian
9 дней назад

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...

github
3 месяца назад

Atom exhaustion: OAuth2 JWT tag: scope values

EPSS

Процентиль: 25%
0.00342
Низкий

5.3 Medium

CVSS3