CVE-2026-66071
RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The token signature is verified first, so the attacker cannot forge scopes , but in IdP configurations where scope content is user-influenced, each login with a novel tag value leaks one In deployments where users can influence the scopes included in their IdP-issued JWT rabbitmqauthbackendoauth2 enabled IdP permits attacker-influenced scope values in signed tokens. This issue is fixed in versions 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1.
| CWE | CWE-400 |
| Vendor | rabbitmq |
| Product | rabbitmq-server |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Get instant alerts for rabbitmq rabbitmq-server
Be the first to know when new unknown vulnerabilities affecting rabbitmq rabbitmq-server are published โ delivered to Slack, Telegram or Discord.