rabbitmq
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting rabbitmq.
- CVE-2026-57217RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass6.5
- CVE-2026-57221RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users5.0
- CVE-2026-57215RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom8.8
- CVE-2026-57219RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations7.5
- CVE-2026-57218RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure6.5
- CVE-2026-57216RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks6.8
- CVE-2026-57220RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS7.5
- CVE-2026-57214RabbitMQ: Stored XSS in RabbitMQ management UI5.4
- CVE-2026-57211RabbitMQ: UNC SSRF affecting the management UI on Windows6.5
- CVE-2026-57212RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size7.7
- CVE-2026-57213RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering4.8
- CVE-2026-44839RabbitMQ: Unsanitized vhost names allow for XSS in management UI4.8
- CVE-2026-44838RabbitMQ MQTT Topic Permission Authorization Bypass8.1
- CVE-2025-50200RabbitMQ Node can log Basic Auth header from an HTTP request5.5
- CVE-2025-30219RabbitMQ has XSS Vulnerability in an Error Message in Management UI6.1