Broadcom Rabbitmq Server vulnerabilities
25 known vulnerabilities affecting broadcom/rabbitmq_server.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM13
Vulnerabilities
Page 1 of 2
CVE-2026-57216P2CRITICALCVSS 10.0≥ 3.13.0, < 4.2.62026-07-10
CVE-2026-57216 [CRITICAL] CWE-287 CVE-2026-57216: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback che
nvd
CVE-2026-57211P2CRITICALCVSS 10.0≥ 4.1.0, < 4.2.62026-07-10
CVE-2026-57211 [CRITICAL] CWE-36 CVE-2026-57211: RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ man
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attack
nvd
CVE-2026-57215P3HIGHCVSS 8.8≥ 3.13.0, < 4.2.62026-07-10
CVE-2026-57215 [HIGH] CWE-863 CVE-2026-57215: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is
nvd
CVE-2026-44838P3HIGHCVSS 8.1≥ 4.2.0, < 4.2.42026-05-27
CVE-2026-44838 [HIGH] CWE-863 CVE-2026-44838: RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin all
RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided b
nvd
CVE-2026-57219P3HIGHCVSS 7.5≥ 3.13.0, < 4.2.62026-07-10
CVE-2026-57219 [HIGH] CWE-200 CVE-2026-57219: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsol
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabl
nvd
CVE-2016-9877P3CRITICALCVSS 9.8v3.0.0v3.0.1+30 more2016-12-29
CVE-2016-9877 [CRITICAL] CWE-284 CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection r
nvd
CVE-2026-57220P3HIGHCVSS 7.5fixed in 4.2.62026-07-10
CVE-2026-57220 [HIGH] CWE-770 CVE-2026-57220: RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This i
nvd
CVE-2026-57212P3HIGHCVSS 7.7≥ 3.13.0, < 4.2.52026-07-10
CVE-2026-57212 [HIGH] CWE-770 CVE-2026-57212: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbi
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4
nvd
CVE-2019-11287P3HIGHCVSS 7.5≥ 3.8.0, < 3.8.12019-11-23
CVE-2019-11287 [HIGH] CWE-400 CVE-2019-11287: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that w
nvd
CVE-2022-31008P3HIGHCVSS 7.5≥ 3.9.0, < 3.9.18≥ 3.10.0, < 3.10.22022-10-06
CVE-2022-31008 [HIGH] CWE-330 CVE-2022-31008: RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and fed
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably eas
nvd
CVE-2026-57217P3MEDIUMCVSS 6.5≥ 3.13.0, < 4.2.62026-07-10
CVE-2026-57217 [MEDIUM] CWE-863 CVE-2026-57217: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.1
nvd
CVE-2021-22117P3HIGHCVSS 7.8≥ 3.8.0, < 3.8.16vRabbitMQ Windows installers prior to version 3.8.162021-05-18
CVE-2021-22117 [HIGH] CWE-94 CVE-2021-22117: RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, p
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
nvd
CVE-2017-4966P3HIGHCVSS 7.8v3.4.0v3.4.1+9 more2017-06-13
CVE-2017-4966 [HIGH] CWE-200 CVE-2017-4966: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions,
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without ex
nvd
CVE-2026-57218P3MEDIUMCVSS 6.5≥ 4.2.0, < 4.2.62026-07-10
CVE-2026-57218 [MEDIUM] CWE-863 CVE-2026-57218: RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed
nvd
CVE-2017-4965P4MEDIUMCVSS 6.1v3.4.0v3.4.1+9 more2017-06-13
CVE-2017-4965 [MEDIUM] CWE-79 CVE-2017-4965: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions,
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd
CVE-2020-5419P4MEDIUMCVSS 6.7≥ 3.8.0, < 3.8.72020-08-31
CVE-2020-5419 [MEDIUM] CWE-427 CVE-2020-5419: RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vuln
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.
nvd
CVE-2017-4967P4MEDIUMCVSS 6.1v3.4.0v3.4.1+9 more2017-06-13
CVE-2017-4967 [MEDIUM] CWE-79 CVE-2017-4967: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions,
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd
CVE-2025-50200P4MEDIUMCVSS 5.5fixed in 4.0.82025-06-19
CVE-2025-50200 [MEDIUM] CWE-532 CVE-2025-50200: RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging auth
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy t
nvd
CVE-2026-57221P4MEDIUMCVSS 5.0≥ 3.13.0, < 4.2.62026-07-10
CVE-2026-57221 [MEDIUM] CWE-862 CVE-2026-57221: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer count
nvd
CVE-2026-57214P4MEDIUMCVSS 5.4≥ 4.2.0, < 4.2.52026-07-10
CVE-2026-57214 [MEDIUM] CWE-79 CVE-2026-57214: RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This
nvd
1 / 2Next →