RabbitMQ 是一种消息和流式代理。在版本 4.1.0 至 4.3.3、4.2.9 和 4.1.11 中,存在一个与安全流管理相关的漏洞:允许低权限节点发起拒绝服务(DoS)攻击。 当 RabbitMQ 4.3.1 启用了 插件时,它允许经过身份验证且能够访问目标虚拟主机(vhost)的管理用户向 接口发送请求。如果请求体中包含 字段,处理程序会解析攻击者控制的逗号分隔字符串,并在检查用户是否有权限配置所生成的流之前,先构建完整的流名称列表。因此,一个拥有 vhost 访问权限但无配置、写入或读取权限的低权限管
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.3.0, < 4.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67236 | 8.2 HIGH | RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST / |
| CVE-2026-67409 | 8.2 HIGH | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Au |
| CVE-2026-67410 | 8.2 HIGH | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint |
| CVE-2026-67239 | 7.6 HIGH | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI |
| CVE-2026-67237 | 7.5 HIGH | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint |
| CVE-2026-67419 | 7.1 HIGH | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work |
| CVE-2026-67226 | 6.9 MEDIUM | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list |
| CVE-2026-61837 | 6.3 MEDIUM | RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authent |
| CVE-2026-67242 | 6.3 MEDIUM | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp |
| CVE-2026-67230 | 6.3 MEDIUM | RabbitMQ: Web-STOMP unbounded pre-auth accumulation |
| CVE-2026-67223 | 6.3 MEDIUM | RabbitMQ: LDAP DN injection via unescaped substitution |
| CVE-2026-67225 | 6.3 MEDIUM | RabbitMQ: Stream-protocol frame length never validated against frame_max |
| CVE-2026-66073 | 6.0 MEDIUM | RabbitMQ: Atom table exhaustion via management API node field |
| CVE-2026-66071 | 6.0 MEDIUM | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values |
| CVE-2026-67413 | 6.0 MEDIUM | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an U |
| CVE-2026-67412 | 6.0 MEDIUM | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message acces |
| CVE-2026-67411 | 6.0 MEDIUM | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass |
| CVE-2026-67222 | 5.9 MEDIUM | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client |
| CVE-2026-67227 | 5.9 MEDIUM | RabbitMQ: Atom exhaustion: to_atom on global-parameter :name |
| CVE-2026-67415 | 5.9 MEDIUM | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Servic |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet