cbcvebase.

Broadcom Rabbitmq Server vulnerabilities

25 known vulnerabilities affecting broadcom/rabbitmq_server.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM13

Vulnerabilities

Page 2 of 2
CVE-2014-9650P4MEDIUMCVSS 5.0v2.1.0v2.1.1+42 more2015-01-27
CVE-2014-9650 [MEDIUM] CVE-2014-9650: CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 a CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
nvd
CVE-2026-57213P4MEDIUMCVSS 4.8≥ 3.13.0, < 4.2.52026-07-10
CVE-2026-57213 [MEDIUM] CWE-79 CVE-2026-57213: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbi RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. Thi
nvd
CVE-2019-11291P4MEDIUMCVSS 4.8≥ 3.7.0, < 3.7.20v3.8.02019-11-22
CVE-2019-11291 [MEDIUM] CWE-79 CVE-2019-11291: Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PC Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site s
nvd
CVE-2026-44839P4MEDIUMCVSS 4.8≥ 3.7.0, < 4.0.13≥ 4.1.0, < 4.1.22026-05-27
CVE-2026-44839 [MEDIUM] CWE-80 CVE-2026-44839: RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerabi RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
nvd
CVE-2014-9649P4MEDIUMCVSS 4.3v2.1.0v2.1.1+42 more2015-01-27
CVE-2014-9649 [MEDIUM] CWE-79 CVE-2014-9649: Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x be Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
nvd
Broadcom Rabbitmq Server vulnerabilities | cvebase