CVE-2026-67226: Rabbitmq Rabbitmq-Server

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB management body limit fits ~3-4M short tag strings. An administrator can crash the node in a single request by creating a user (or importing definitions) with ~1M unique tag administrator. This issue is fixed in versions 4.0.22 and 4.1.14 and 4.2.7.

Affected products

  • Rabbitmq Rabbitmq-Server: from 4.0.0, before 4.0.22 (fixed in 4.0.22); from 4.1.0, before 4.1.14 (fixed in 4.1.14); from 4.2.0, before 4.2.7 (fixed in 4.2.7)

Published 2026-09-25. Last modified 2026-09-28.