RabbitMQ 是一个消息代理和流媒体处理系统。在版本 3.13.0 至 3.13.18、4.0.23、4.1.14、4.2.9 和 4.3.3 之间(包括这些版本边界),存在“JWKS 获取时忽略 HTTP 响应状态码导致签名密钥销毁从而引发认证拒绝服务”的安全漏洞(CWE-252)。 在文件 中,JWKS 密钥获取机制在从 OAuth2 提供商的 JWKS 端点下载签名密钥时,未对 HTTP 响应状态码进行验证。非 200 状态码的响应(包括 4xx 客户端错误和 5xx 服务器错误)被当作成功响应来处理。当
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.3.0, < 4.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67236 | 8.2 HIGH | RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST / |
| CVE-2026-67410 | 8.2 HIGH | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint |
| CVE-2026-67239 | 7.6 HIGH | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI |
| CVE-2026-67237 | 7.5 HIGH | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint |
| CVE-2026-67408 | 7.1 HIGH | RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node |
| CVE-2026-67419 | 7.1 HIGH | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work |
| CVE-2026-67226 | 6.9 MEDIUM | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list |
| CVE-2026-61837 | 6.3 MEDIUM | RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authent |
| CVE-2026-67242 | 6.3 MEDIUM | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp |
| CVE-2026-67230 | 6.3 MEDIUM | RabbitMQ: Web-STOMP unbounded pre-auth accumulation |
| CVE-2026-67223 | 6.3 MEDIUM | RabbitMQ: LDAP DN injection via unescaped substitution |
| CVE-2026-67225 | 6.3 MEDIUM | RabbitMQ: Stream-protocol frame length never validated against frame_max |
| CVE-2026-66073 | 6.0 MEDIUM | RabbitMQ: Atom table exhaustion via management API node field |
| CVE-2026-66071 | 6.0 MEDIUM | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values |
| CVE-2026-67413 | 6.0 MEDIUM | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an U |
| CVE-2026-67412 | 6.0 MEDIUM | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message acces |
| CVE-2026-67411 | 6.0 MEDIUM | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass |
| CVE-2026-67222 | 5.9 MEDIUM | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client |
| CVE-2026-67227 | 5.9 MEDIUM | RabbitMQ: Atom exhaustion: to_atom on global-parameter :name |
| CVE-2026-67415 | 5.9 MEDIUM | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Servic |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet