RabbitMQ rabbitmq-server是RabbitMQ组织的消息队列中间件。 rabbitmq-server存在跨站脚本漏洞,该漏洞源于rabbitmq_federation_management插件在Federation Status页面上渲染consumer_tag字段时未进行HTML转义,可能导致能配置federation上游或策略的用户在查看该页面的用户浏览器中执行JavaScript。以下版本受到影响:3.13.14之前版本、4.0.19之前版本、4.1.10之前版本和4.2.5之前
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.2.0, < 4.2.5 |
affected |
>= 4.1.0, < 4.1.10 |
affected | ||
>= 4.0.0, < 4.0.19 |
affected | ||
>= 3.13.0, < 3.13.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.2.0, < 4.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57219 | 8.7 HIGH | RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint |
| CVE-2026-57220 | 7.5 HIGH | RabbitMQ: Stream listener does not enforce configured frame-size limit during authenticati |
| CVE-2026-57216 | 6.8 MEDIUM | RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote gu |
| CVE-2026-57211 | 6.5 MEDIUM | RabbitMQ: UNC SSRF affecting the management UI on Windows |
| CVE-2026-57218 | RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-re | |
| CVE-2026-57214 | RabbitMQ: Stored XSS in RabbitMQ management UI | |
| CVE-2026-57217 | RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass | |
| CVE-2026-57212 | RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_s | |
| CVE-2026-57215 | RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injec | |
| CVE-2026-57221 | RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue |
No comments yet