Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

rabbitmq — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting rabbitmq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RabbitMQ serves as a widely adopted message broker for enterprise messaging and queuing systems, enabling reliable communication between distributed applications. Historically, it has been susceptible to remote code execution vulnerabilities through deserialization flaws, cross-site scripting in management interfaces, and privilege escalation via authentication bypasses. The platform's default configurations often present attack surfaces, with past incidents including unauthorized access through exposed management consoles and credential stuffing attacks. While RabbitMQ maintains a relatively low CVE count compared to similar systems, its complex architecture requires careful hardening to prevent exploitation of common misconfigurations and access control weaknesses.

CVE IDTitleCVSSSeverityPublished
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass — rabbitmq-serverCWE-863--2026-07-10
CVE-2026-57221 RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users — rabbitmq-serverCWE-862--2026-07-10
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom — rabbitmq-serverCWE-863--2026-07-10
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations — rabbitmq-serverCWE-200 8.7 High2026-07-10
CVE-2026-57218 RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure — rabbitmq-serverCWE-863--2026-07-10
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks — rabbitmq-serverCWE-287 6.8 Medium2026-07-10
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS — rabbitmq-serverCWE-770 7.5 High2026-07-10
CVE-2026-57214 RabbitMQ: Stored XSS in RabbitMQ management UI — rabbitmq-serverCWE-79--2026-07-10
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows — rabbitmq-serverCWE-36 6.5 Medium2026-07-10
CVE-2026-57212 RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size — rabbitmq-serverCWE-770--2026-07-10
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering — rabbitmq-serverCWE-79--2026-07-10
CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI — rabbitmq-serverCWE-80--2026-05-27
CVE-2026-44838 RabbitMQ MQTT Topic Permission Authorization Bypass — rabbitmq-serverCWE-863--2026-05-27
CVE-2025-50200 RabbitMQ Node can log Basic Auth header from an HTTP request — rabbitmq-serverCWE-532 6.8AIMediumAI2025-06-19
CVE-2025-30219 RabbitMQ has XSS Vulnerability in an Error Message in Management UI — rabbitmq-serverCWE-79 6.1 Medium2025-03-25
CVE-2024-51988 HTTP API's queue deletion endpoint does not verify that the user has a required permission — rabbitmq-serverCWE-284 6.5 Medium2024-11-06
CVE-2023-46118 Denial of Service by publishing large messages over the HTTP API — rabbitmq-serverCWE-400 4.9 Medium2023-10-24
CVE-2023-46120 RabbitMQ Java client's lack of message size limitation leads to remote DoS attack — rabbitmq-java-clientCWE-400 4.9 Medium2023-10-24
CVE-2022-31008 Predictable credential obfuscation seed value used in rabbitmq-server — rabbitmq-serverCWE-330 5.5 Medium2022-10-06
CVE-2021-32719 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management plugin — rabbitmq-serverCWE-80 3.1 Low2021-06-28
CVE-2021-32718 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ management UI — rabbitmq-serverCWE-80 3.1 Low2021-06-28

This page lists every published CVE security advisory associated with rabbitmq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.