Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

rabbitmq — Vulnerabilities & Security Advisories 93

Browse all 93 CVE security advisories affecting rabbitmq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

RabbitMQ serves as a widely adopted message broker for enterprise messaging and queuing systems, enabling reliable communication between distributed applications. Historically, it has been susceptible to remote code execution vulnerabilities through deserialization flaws, cross-site scripting in management interfaces, and privilege escalation via authentication bypasses. The platform's default configurations often present attack surfaces, with past incidents including unauthorized access through exposed management consoles and credential stuffing attacks. While RabbitMQ maintains a relatively low CVE count compared to similar systems, its complex architecture requires careful hardening to prevent exploitation of common misconfigurations and access control weaknesses.

CVE ID Title CVSS Severity Published
CVE-2026-77410 RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation — amqp091-go CWE-789 8.9 High 2026-09-16
CVE-2026-77406 RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration — amqp091-go CWE-195 8.2 High 2026-09-16
CVE-2026-77403 RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation — amqp091-go CWE-770 8.9 High 2026-09-16
CVE-2026-77407 RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields — amqp091-go CWE-316 7.0 High 2026-09-16
CVE-2026-77408 RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow — amqp091-go CWE-190 9.1 Critical 2026-09-16
CVE-2026-79921 amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload — amqp091-go CWE-770 8.9 High 2026-08-26
CVE-2026-61634 RabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_max — rabbitmq-java-client CWE-20 - - 2026-08-18
CVE-2026-63336 RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM — rabbitmq-java-client CWE-295 5.1 Medium 2026-08-18
CVE-2026-63337 RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading — rabbitmq-java-client CWE-470 7.5 High 2026-08-18
CVE-2026-69220 RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS — rabbitmq-java-client CWE-674 8.7 High 2026-08-18
CVE-2026-69219 RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation — rabbitmq-java-client CWE-789 8.7 High 2026-08-18
CVE-2026-63335 RabbitMQ Java client malformed body frame triggers raw command assembler exception — rabbitmq-java-client CWE-20 6.3 Medium 2026-08-18
CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass — rabbitmq-server CWE-863 - - 2026-07-10
CVE-2026-57221 RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users — rabbitmq-server CWE-862 - - 2026-07-10
CVE-2026-57215 RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom — rabbitmq-server CWE-863 - - 2026-07-10
CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations — rabbitmq-server CWE-200 8.7 High 2026-07-10
CVE-2026-57218 RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure — rabbitmq-server CWE-863 - - 2026-07-10
CVE-2026-57216 RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks — rabbitmq-server CWE-287 6.8 Medium 2026-07-10
CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS — rabbitmq-server CWE-770 7.5 High 2026-07-10
CVE-2026-57214 RabbitMQ: Stored XSS in RabbitMQ management UI — rabbitmq-server CWE-79 - - 2026-07-10
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows — rabbitmq-server CWE-36 6.5 Medium 2026-07-10
CVE-2026-57212 RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size — rabbitmq-server CWE-770 - - 2026-07-10
CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering — rabbitmq-server CWE-79 - - 2026-07-10
CVE-2026-44839 RabbitMQ: Unsanitized vhost names allow for XSS in management UI — rabbitmq-server CWE-80 - - 2026-05-27
CVE-2026-44838 RabbitMQ MQTT Topic Permission Authorization Bypass — rabbitmq-server CWE-863 - - 2026-05-27
CVE-2025-50200 RabbitMQ Node can log Basic Auth header from an HTTP request — rabbitmq-server CWE-532 6.8AI Medium AI 2025-06-19
CVE-2025-30219 RabbitMQ has XSS Vulnerability in an Error Message in Management UI — rabbitmq-server CWE-79 6.1 Medium 2025-03-25
CVE-2024-51988 HTTP API's queue deletion endpoint does not verify that the user has a required permission — rabbitmq-server CWE-284 6.5 Medium 2024-11-06
CVE-2023-46118 Denial of Service by publishing large messages over the HTTP API — rabbitmq-server CWE-400 4.9 Medium 2023-10-24
CVE-2023-46120 RabbitMQ Java client's lack of message size limitation leads to remote DoS attack — rabbitmq-java-client CWE-400 4.9 Medium 2023-10-24

This page lists every published CVE security advisory associated with rabbitmq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.