cbcvebase.

Rabbitmq Rabbitmq-Server vulnerabilities

34 known vulnerabilities affecting rabbitmq/rabbitmq-server.

Total CVEs
34
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM21LOW1

Vulnerabilities

Page 2 of 2
CVE-2025-50200P4MEDIUMCVSS 5.5≤ 3.13.72025-06-19
CVE-2025-50200 [MEDIUM] CWE-532 CVE-2025-50200: RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging auth RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy t
nvdosv
CVE-2026-57221P4MEDIUMCVSS 5.0v>= 4.2.0, < 4.2.6v>= 4.1.0, < 4.1.11+2 more2026-07-10
CVE-2026-57221 [MEDIUM] CWE-862 CVE-2026-57221: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer count
nvd
CVE-2025-30219P4MEDIUMCVSS 6.1fixed in 4.0.32025-03-25
CVE-2025-30219 [MEDIUM] CWE-79 CVE-2025-30219: RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophistica RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node
nvdosv
CVE-2021-32718P4MEDIUMCVSS 5.4fixed in 3.8.172021-06-28
CVE-2021-32718 [MEDIUM] CWE-80 CVE-2021-32718: RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new use RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the us
nvdosv
CVE-2026-57214P4MEDIUMCVSS 5.4v>= 4.2.0, < 4.2.52026-07-10
CVE-2026-57214 [MEDIUM] CWE-79 CVE-2026-57214: RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This
nvd
CVE-2014-9650P4MEDIUMCVSS 5.0≥ 0, < 3.4.1-12015-01-27
CVE-2014-9650 [MEDIUM] CVE-2014-9650: CRLF injection vulnerability in the management plugin in RabbitMQ 2 CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
osv
CVE-2026-57213P4MEDIUMCVSS 4.8v>= 4.2.0, < 4.2.5v>= 4.1.0, < 4.1.10+2 more2026-07-10
CVE-2026-57213 [MEDIUM] CWE-79 CVE-2026-57213: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbi RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. Thi
nvd
CVE-2021-32719P4MEDIUMCVSS 4.8fixed in 3.8.182021-06-28
CVE-2021-32719 [MEDIUM] CWE-80 CVE-2021-32719: RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a fe RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page.
nvdosv
CVE-2023-46118P4MEDIUMCVSS 4.9fixed in 3.12.7fixed in 3.11.242023-10-25
CVE-2023-46118 [MEDIUM] CWE-400 CVE-2023-46118: RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP reques RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of
nvdosv
CVE-2019-11281P4MEDIUMCVSS 4.8≥ 0, < 3.7.18-12019-10-16
CVE-2019-11281 [MEDIUM] CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3 Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would g
osv
CVE-2019-11291P4MEDIUMCVSS 4.8≥ 0, < 3.8.3-12019-11-22
CVE-2019-11291 [MEDIUM] CVE-2019-11291: Pivotal RabbitMQ, 3 Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hos
osv
CVE-2026-44839P4MEDIUMCVSS 4.8v>= 3.7.0, < 4.0.13v>= 4.1.0-alpha, < 4.1.22026-05-27
CVE-2026-44839 [MEDIUM] CWE-80 CVE-2026-44839: RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerabi RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
nvd
CVE-2014-9649P4MEDIUMCVSS 4.3≥ 0, < 3.4.1-12015-01-27
CVE-2014-9649 [MEDIUM] CVE-2014-9649: Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2 Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
osv
CVE-2015-0862P4LOWCVSS 3.5≥ 0, < 3.4.3-12015-01-18
CVE-2015-0862 [LOW] CVE-2015-0862: Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3 Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing polic
osv