CyberRota Analysis
AI-GeneratedRabbitMQ versions prior to 4.2.7 and 4.3.1 are vulnerable to a denial-of-service attack due to improper handling of caller-supplied ETF-encoded binaries, which can lead to the crashing of the entire Erlang VM when an authenticated AMQP client sends approximately 1 million requests. This vulnerability affects all vhosts and connections, making it critical for organizations using RabbitMQ in environments where authenticated AMQP clients are present to prioritize upgrading to the patched versions. Immediate action is recommended for users who do not implement strict rate limiting on connections.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, utf8) on the node-name field. It is reached from rabbit_volatile_queue:pid_from_name/2, which is invoked for any queue name / routing key beginning amq.rabbitmq.reply-to.. The CandidateNodes membership check happens after the atom is created, and the surrounding try/catch cannot reclaim atoms (they are never GC'd). binary_to_existing_atom is not used. Any authenticated AMQP client can crash the entire Erlang VM (all vhosts, all connections) with ~1M cheap requests. Preconditions include Authenticated AMQP 0-9-1 connection to any vhost No per-connection rate limit low enough to make ~1M operations infeasible. This issue is fixed in versions 4.2.7 and 4.3.1.