BIT-rabbitmq-2026-66071

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/rabbitmq/BIT-rabbitmq-2026-66071.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-rabbitmq-2026-66071
Aliases
Published
2026-10-01T09:32:47Z
Modified
2026-10-01T10:11:13Z
Summary
RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values
Details

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The token signature is verified first, so the attacker cannot forge scopes , but in IdP configurations where scope content is user-influenced, each login with a novel tag value leaks one In deployments where users can influence the scopes included in their IdP-issued JWT rabbitmqauthbackendoauth2 enabled IdP permits attacker-influenced scope values in signed tokens. This issue is fixed in versions 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:*:*:*"
    ],
    "severity":  "Medium"
}
References

Affected packages

Bitnami / rabbitmq

Package

Name
rabbitmq
Purl
pkg:bitnami/rabbitmq

Severity

  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.13.0
Fixed
3.13.15
Introduced
4.0.0
Fixed
4.0.22
Introduced
4.1.0
Fixed
4.1.11
Introduced
4.2.0
Fixed
4.2.6
Introduced
4.3.0
Fixed
4.3.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/rabbitmq/BIT-rabbitmq-2026-66071.json"