RabbitMQ 是一种消息和流式传输代理。在 3.13.0 至 3.13.18、4.0.23、4.1.14、4.2.9 以及 4.3.4 版本中,当启用了 OAuth 管理界面时,RabbitMQ Management 会将包含攻击者可控队列名称的 AMQP 授权错误原因信息以 HTML 形式渲染。 要利用此漏洞,攻击者需要具备队列配置权限,并有一位只能查看但不能读取该队列的管理员用户,且该管理员需点击“Get Message(s)”(获取消息)按钮。此时,如果队列名称中包含 元素,则可能劫持基于自动相对刷新的行
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.19 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67236 | 8.2 HIGH | RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST / |
| CVE-2026-67409 | 8.2 HIGH | RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Au |
| CVE-2026-67410 | 8.2 HIGH | RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint |
| CVE-2026-67239 | 7.6 HIGH | RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI |
| CVE-2026-67237 | 7.5 HIGH | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint |
| CVE-2026-67408 | 7.1 HIGH | RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node |
| CVE-2026-67419 | 7.1 HIGH | RabbitMQ: Consecutive topic wildcards cause combinatorial routing work |
| CVE-2026-67226 | 6.9 MEDIUM | RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list |
| CVE-2026-61837 | 6.3 MEDIUM | RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authent |
| CVE-2026-67242 | 6.3 MEDIUM | RabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float exp |
| CVE-2026-67230 | 6.3 MEDIUM | RabbitMQ: Web-STOMP unbounded pre-auth accumulation |
| CVE-2026-67223 | 6.3 MEDIUM | RabbitMQ: LDAP DN injection via unescaped substitution |
| CVE-2026-67225 | 6.3 MEDIUM | RabbitMQ: Stream-protocol frame length never validated against frame_max |
| CVE-2026-67411 | 6.0 MEDIUM | RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass |
| CVE-2026-66073 | 6.0 MEDIUM | RabbitMQ: Atom table exhaustion via management API node field |
| CVE-2026-67412 | 6.0 MEDIUM | RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message acces |
| CVE-2026-67413 | 6.0 MEDIUM | RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an U |
| CVE-2026-66071 | 6.0 MEDIUM | RabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope values |
| CVE-2026-67415 | 5.9 MEDIUM | RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Servic |
| CVE-2026-67222 | 5.9 MEDIUM | RabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_client |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet