Vulnerabilidades en rabbitmq
65 resultadosAnálisis Vexday
RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.
CVE-2026-77410HIGHRabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer AllocationEPSS 0.5%CVE-2026-77408CRITICALRabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer OverflowEPSS 0.5%CVE-2026-77403HIGHRabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size NegotiationEPSS 0.5%CVE-2026-63335MEDIUMRabbitMQ Java client malformed body frame triggers raw command assembler exceptionEPSS 0.5%CVE-2026-61634NONERabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxEPSS 0.5%CVE-2026-57221MEDIUMRabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged usersEPSS 0.5%CVE-2026-57213MEDIUMRabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag renderingEPSS 0.4%CVE-2026-66070HIGHRabbitMQ: CORS * reflects Origin with Allow-CredentialsEPSS 0.4%CVE-2026-77406HIGHRabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos ConfigurationEPSS 0.4%CVE-2026-66069LOWRabbitMQ: Monitoring-tag DELETE of auth-attempt metricsEPSS 0.4%CVE-2026-57214HIGHRabbitMQ: Stored XSS in RabbitMQ management UIEPSS 0.4%CVE-2026-67224LOWRabbitMQ: Admin path-traversal write via trace nameEPSS 0.4%CVE-2026-67232HIGHRabbitMQ: Web-MQTT decompression bombEPSS 0.4%CVE-2024-51988MEDIUMHTTP API's queue deletion endpoint does not verify that the user has a required permissionEPSS 0.4%CVE-2026-44838MEDIUMRabbitMQ MQTT Topic Permission Authorization BypassEPSS 0.4%CVE-2026-66067MEDIUMRabbitMQ: Stream protocol skips per vhost per user connection limitsEPSS 0.4%CVE-2022-31008MEDIUMPredictable credential obfuscation seed value used in rabbitmq-serverEPSS 0.3%CVE-2026-67218LOWRabbitMQ: Super-stream HTTP creation skips configure-permission checkEPSS 0.3%CVE-2026-66074MEDIUMRabbitMQ: ReDoS via management API ?name= filterEPSS 0.3%CVE-2026-66072MEDIUMRabbitMQ: Atom table exhaustion via stream `chunk_selector`EPSS 0.3%