Resource exhaustion in RabbitMQ Server - #VU139301
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to cause a persistent broker-wide denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Shovel runtime parameter parser when handling management API requests that set Shovel runtime parameters. A remote privileged user can submit crafted Shovel parameter values with many unique atom-producing fields to cause a persistent broker-wide denial of service.
Only instances with the rabbitmq_shovel and rabbitmq_shovel_management plugins enabled are vulnerable. Stored malicious Shovel parameters can be reparsed after a broker restart, recreating atom pressure without another live request.