Vulnerabilities in rabbitmq
93 resultsVexday analysis
RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.
CVE-2026-77407HIGHRabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct FieldsEPSS 0.1%CVE-2026-67405MEDIUMRabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)EPSS 0.1%CVE-2026-66068MEDIUMRabbitMQ: Shovel DEBUG log of full state exposes decrypted URIsEPSS 0.1%CVE-2026-77404HIGHRabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter InjectionEPSS 0.1%CVE-2026-67408HIGHRabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of ServiceEPSS —CVE-2026-67241MEDIUMRabbitMQ: AMQP 1.0 management exchange.declare skips alternate-exchange permission checkEPSS —CVE-2026-67230MEDIUMRabbitMQ: Web-STOMP unbounded pre-auth accumulationEPSS —CVE-2026-66073MEDIUMRabbitMQ: Atom table exhaustion via management API node fieldEPSS —CVE-2026-66078LOWRabbitMQ: protected tag bypass via bulk-deleteEPSS —CVE-2026-67223MEDIUMRabbitMQ: LDAP DN injection via unescaped substitutionEPSS —CVE-2026-66071MEDIUMRabbitMQ: Atom exhaustion: OAuth2 JWT tag: scope valuesEPSS —CVE-2026-67237HIGHRabbitMQ: Reflected XSS via the OAuth bootstrap JS endpointEPSS —CVE-2026-67242MEDIUMRabbitMQ: OAuth2 is_integer(Exp) guard skips token-expiry checks for float expEPSS —CVE-2026-67222MEDIUMRabbitMQ: list_to_atom on auth_mechanism URI tokens in amqp_clientEPSS —CVE-2026-67407MEDIUMRabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypassEPSS —CVE-2026-67234LOWRabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preferenceEPSS —CVE-2026-67420LOWRabbitMQ OAuth credential refresh retains revoked runtime tagsEPSS —CVE-2026-67410HIGHRabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript EndpointEPSS —CVE-2026-67226MEDIUMRabbitMQ: Admin-only atom exhaustion: PUT /api/users tags listEPSS —CVE-2026-67409HIGHRabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoSEPSS —