RabbitMQ 是一种消息传递和流式传输代理。在 4.0.0 至 4.0.23、4.1.14、4.2.9 和 4.3.3 版本中,可选插件 的 交换器接受由客户端控制的 绑定表达式,其中 评估器会将百分号( )和下划线( )通配符展开为重叠的 PCRE(Perl 兼容正则表达式)片段。这些片段通过原始调用 执行,且未设置匹配次数或递归深度限制。这使得拥有绑定和发布权限的已认证租户可以通过构造恶意的选择器表达式,消耗代理调度器的 CPU 资源,从而造成拒绝服务(DoS)漏洞。该问题已在版本 4.0.23、4.1.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.2.0, < 4.2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67236 | 8.2 HIGH | RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST / |
| CVE-2026-67409 | 8.2 HIGH | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Au |
| CVE-2026-67410 | 8.2 HIGH | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint |
| CVE-2026-67239 | 7.6 HIGH | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI |
| CVE-2026-67237 | 7.5 HIGH | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint |
| CVE-2026-67408 | 7.1 HIGH | RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node |
| CVE-2026-67419 | 7.1 HIGH | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work |
| CVE-2026-67226 | 6.9 MEDIUM | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list |
| CVE-2026-61837 | 6.3 MEDIUM | RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authent |
| CVE-2026-67242 | 6.3 MEDIUM | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp |
| CVE-2026-67230 | 6.3 MEDIUM | RabbitMQ: Web-STOMP unbounded pre-auth accumulation |
| CVE-2026-67223 | 6.3 MEDIUM | RabbitMQ: LDAP DN injection via unescaped substitution |
| CVE-2026-67225 | 6.3 MEDIUM | RabbitMQ: Stream-protocol frame length never validated against frame_max |
| CVE-2026-67411 | 6.0 MEDIUM | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass |
| CVE-2026-66073 | 6.0 MEDIUM | RabbitMQ: Atom table exhaustion via management API node field |
| CVE-2026-67412 | 6.0 MEDIUM | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message acces |
| CVE-2026-66071 | 6.0 MEDIUM | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values |
| CVE-2026-67415 | 5.9 MEDIUM | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Servic |
| CVE-2026-67222 | 5.9 MEDIUM | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client |
| CVE-2026-67227 | 5.9 MEDIUM | RabbitMQ: Atom exhaustion: to_atom on global-parameter :name |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet