Vulnerabilidades en rabbitmq

65 resultados
Análisis Vexday

RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.

CVE-2026-57219HIGHRabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsEPSS 2.0%CVE-2021-32718LOWImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ management UIEPSS 1.4%CVE-2021-32719LOWImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management pluginEPSS 1.4%CVE-2023-46118MEDIUMDenial of Service by publishing large messages over the HTTP APIEPSS 1.1%CVE-2023-46120MEDIUMRabbitMQ Java client's lack of message size limitation leads to remote DoS attackEPSS 1.1%CVE-2026-57220HIGHRabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoSEPSS 1.0%CVE-2026-57216MEDIUMRabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checksEPSS 0.9%CVE-2026-57212HIGHRabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_sizeEPSS 0.7%CVE-2026-69219HIGHRabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocationEPSS 0.7%CVE-2026-69220HIGHRabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoSEPSS 0.7%CVE-2026-57215HIGHRabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantomEPSS 0.7%CVE-2026-57211MEDIUMRabbitMQ: UNC SSRF affecting the management UI on WindowsEPSS 0.6%CVE-2026-57218MEDIUMRabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosureEPSS 0.6%CVE-2026-57217HIGHRabbitMQ: Topic authorization can lead to cross-tenant routing-key bypassEPSS 0.6%CVE-2026-63337HIGHRabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loadingEPSS 0.6%CVE-2026-75516HIGHRabbitMQ Java client: Frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcementEPSS 0.6%CVE-2026-79921HIGHamqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized PayloadEPSS 0.5%CVE-2026-77408CRITICALRabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer OverflowEPSS 0.5%CVE-2026-77410HIGHRabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer AllocationEPSS 0.5%CVE-2026-77409HIGHRabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel BlockingEPSS 0.5%