cbcvebase.

Rabbitmq Rabbitmq-Server vulnerabilities

34 known vulnerabilities affecting rabbitmq/rabbitmq-server.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM21LOW1

Vulnerabilities

Page 1 of 2
CVE-2026-57216P2CRITICALCVSS 10.0v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.11+2 more2026-07-10
CVE-2026-57216 [CRITICAL] CWE-287 CVE-2026-57216: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9- RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback che
nvd
CVE-2026-57211P2CRITICALCVSS 10.0v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.112026-07-10
CVE-2026-57211 [CRITICAL] CWE-36 CVE-2026-57211: RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ man RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attack
nvd
CVE-2026-57215P3HIGHCVSS 8.8v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.11+2 more2026-07-10
CVE-2026-57215 [HIGH] CWE-863 CVE-2026-57215: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is
nvd
CVE-2026-44838P3HIGHCVSS 8.1v>= 4.2.0, < 4.2.42026-05-27
CVE-2026-44838 [HIGH] CWE-863 CVE-2026-44838: RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin all RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided b
nvd
CVE-2026-57219P3HIGHCVSS 7.5v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.11+2 more2026-07-10
CVE-2026-57219 [HIGH] CWE-200 CVE-2026-57219: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsol RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabl
nvd
CVE-2016-9877P3CRITICALCVSS 9.8≥ 0, < 3.6.6-12016-12-29
CVE-2016-9877 [CRITICAL] CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3 An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certifi
osv
CVE-2026-57220P3HIGHCVSS 7.5v>= 4.2.0, < 4.2.62026-07-10
CVE-2026-57220 [HIGH] CWE-770 CVE-2026-57220: RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This i
nvd
CVE-2026-57212P3HIGHCVSS 7.7v>= 4.2.0, < 4.2.5v>= 4.1.0, < 4.1.10+2 more2026-07-10
CVE-2026-57212 [HIGH] CWE-770 CVE-2026-57212: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbi RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4
nvd
CVE-2021-22116P3HIGHCVSS 7.5≥ 0, < 3.9.4-12021-06-08
CVE-2021-22116 [HIGH] CVE-2021-22116: RabbitMQ all versions prior to 3 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.
osv
CVE-2019-11287P3HIGHCVSS 7.5≥ 0, < 3.5.7-1ubuntu0.16.04.4+esm1≥ 0, < 3.6.10-1ubuntu0.5+1 more2021-06-24
CVE-2019-11287 [HIGH] rabbitmq-server vulnerabilities rabbitmq-server vulnerabilities It was discovered that RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11287) Jonathan Knudsen discovered RabbitMQ incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-22116)
osv
CVE-2022-31008P3HIGHCVSS 7.5fixed in 3.8.32v>= 3.9.0, < 3.9.18+1 more2022-10-06
CVE-2022-31008 [HIGH] CWE-330 CVE-2022-31008: RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and fed RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably eas
nvdosv
CVE-2026-57217P3MEDIUMCVSS 6.5v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.11+2 more2026-07-10
CVE-2026-57217 [MEDIUM] CWE-863 CVE-2026-57217: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.1
nvd
CVE-2017-4966P3HIGHCVSS 7.8≥ 0, < 3.6.10-12017-06-13
CVE-2017-4966 [HIGH] CVE-2017-4966: An issue was discovered in these Pivotal RabbitMQ versions: all 3 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve t
osv
CVE-2024-51988P3MEDIUMCVSS 6.5vOpen source RabbitMQ: >= 3.12.7, < 3.12.11vTanzu RabbitMQ: >= 2.0.0, < 3.13.0+1 more2024-11-06
CVE-2024-51988 [MEDIUM] CWE-284 CVE-2024-51988: RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queu RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deleti
nvdosv
CVE-2026-57218P3MEDIUMCVSS 6.5v>= 4.2.0, < 4.2.62026-07-10
CVE-2026-57218 [MEDIUM] CWE-863 CVE-2026-57218: RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed
nvd
CVE-2018-1279P4MEDIUMCVSS 6.5≥ 0, < 3.9.8-52018-12-10
CVE-2018-1279 [MEDIUM] CVE-2018-1279: Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenan Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server
osv
CVE-2017-4965P4MEDIUMCVSS 6.1≥ 0, < 3.6.10-12017-06-13
CVE-2017-4965 [MEDIUM] CVE-2017-4965: An issue was discovered in these Pivotal RabbitMQ versions: all 3 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
osv
CVE-2014-9494P4MEDIUMCVSS 5.0≥ 0, < 3.4.1-12015-01-20
CVE-2014-9494 [MEDIUM] CVE-2014-9494: RabbitMQ before 3 RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
osv
CVE-2015-8786P4MEDIUMCVSS 6.5≥ 0, < 3.6.5-12016-12-09
CVE-2015-8786 [MEDIUM] CVE-2015-8786: The Management plugin in RabbitMQ before 3 The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
osv
CVE-2017-4967P4MEDIUMCVSS 6.1≥ 0, < 3.6.10-12017-06-13
CVE-2017-4967 [MEDIUM] CVE-2017-4967: An issue was discovered in these Pivotal RabbitMQ versions: all 3 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
osv
Rabbitmq Rabbitmq-Server vulnerabilities | cvebase