Vulnerabilities in rabbitmq

21 results
Vexday analysis

RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.

CVE-2021-32718LOWImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ management UIEPSS 1.4%CVE-2021-32719LOWImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management pluginEPSS 1.4%CVE-2023-46118MEDIUMDenial of Service by publishing large messages over the HTTP APIEPSS 1.1%CVE-2023-46120MEDIUMRabbitMQ Java client's lack of message size limitation leads to remote DoS attackEPSS 1.1%CVE-2026-57219HIGHRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsEPSS 0.8%CVE-2026-57220HIGHRabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSEPSS 0.5%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.5%CVE-2026-57212HIGHRabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_sizeEPSS 0.4%CVE-2026-57211MEDIUMRabbitMQ: UNC SSRF affecting the management UI on WindowsEPSS 0.4%CVE-2026-57221MEDIUMRabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged usersEPSS 0.4%CVE-2026-57215HIGHRabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantomEPSS 0.4%CVE-2024-51988MEDIUMHTTP API's queue deletion endpoint does not verify that the user has a required permissionEPSS 0.4%CVE-2026-57217HIGHRabbitMQ: Topic authorization can lead to cross-tenant routing-key bypassEPSS 0.4%CVE-2026-57218MEDIUMRabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosureEPSS 0.4%CVE-2022-31008MEDIUMPredictable credential obfuscation seed value used in rabbitmq-serverEPSS 0.3%CVE-2026-57213MEDIUMRabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag renderingEPSS 0.3%CVE-2026-44838MEDIUMRabbitMQ MQTT Topic Permission Authorization BypassEPSS 0.3%CVE-2026-57214HIGHRabbitMQ: Stored XSS in RabbitMQ management UIEPSS 0.2%CVE-2025-30219MEDIUMRabbitMQ has XSS Vulnerability in an Error Message in Management UIEPSS 0.2%CVE-2025-50200MEDIUMRabbitMQ Node can log Basic Auth header from an HTTP requestEPSS 0.2%