Vulnerabilities in rabbitmq

93 results
Vexday analysis

RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.

CVE-2026-67227MEDIUMRabbitMQ: Atom exhaustion: to_atom on global-parameter :nameEPSS —CVE-2026-67239HIGHRabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UIEPSS —CVE-2026-67412MEDIUMRabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message accessEPSS —CVE-2026-67225MEDIUMRabbitMQ: Stream-protocol frame length never validated against frame_maxEPSS —CVE-2026-67406MEDIUMRabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_statusEPSS —CVE-2026-67411MEDIUMRabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypassEPSS —CVE-2026-67421MEDIUMRabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error HandlingEPSS —CVE-2026-67419HIGHRabbitMQ: Consecutive topic wildcards cause combinatorial routing workEPSS —CVE-2026-67415MEDIUMRabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of ServiceEPSS —CVE-2026-67236HIGHRabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /loginEPSS —CVE-2026-61837MEDIUMRabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checksEPSS —CVE-2026-67233MEDIUMRabbitMQ: Monitoring-tag user can DELETE shovelsEPSS —CVE-2026-67413MEDIUMRabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular ExpressionEPSS —