Vulnerabilidades em rabbitmq

64 resultados
Análise Vexday

RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.

CVE-2026-77409HIGHRabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel BlockingEPSS 0.4%CVE-2026-77410HIGHRabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer AllocationEPSS 0.4%CVE-2026-77412HIGHRabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP ClientEPSS 0.4%CVE-2026-69220HIGHRabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoSEPSS 0.4%CVE-2026-57214HIGHRabbitMQ: Stored XSS in RabbitMQ management UIEPSS 0.4%CVE-2026-63335MEDIUMRabbitMQ Java client malformed body frame triggers raw command assembler exceptionEPSS 0.4%CVE-2024-51988MEDIUMHTTP API's queue deletion endpoint does not verify that the user has a required permissionEPSS 0.4%CVE-2022-31008MEDIUMPredictable credential obfuscation seed value used in rabbitmq-serverEPSS 0.3%CVE-2026-63337HIGHRabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loadingEPSS 0.3%CVE-2026-79921HIGHamqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized PayloadEPSS 0.3%CVE-2026-61634NONERabbitMQ Java client accepts broker frames larger than the negotiated AMQP frame_maxEPSS 0.3%CVE-2026-44838MEDIUMRabbitMQ MQTT Topic Permission Authorization BypassEPSS 0.3%CVE-2026-77405CRITICALRabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI ParserEPSS 0.2%CVE-2025-50200MEDIUMRabbitMQ Node can log Basic Auth header from an HTTP requestEPSS 0.2%CVE-2025-30219MEDIUMRabbitMQ has XSS Vulnerability in an Error Message in Management UIEPSS 0.2%CVE-2026-63336MEDIUMRabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITMEPSS 0.2%CVE-2026-44839MEDIUMRabbitMQ: Unsanitized vhost names allow for XSS in management UIEPSS 0.2%CVE-2026-77407HIGHRabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct FieldsEPSS 0.1%CVE-2026-77404HIGHRabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter InjectionEPSS 0.1%CVE-2026-67224LOWRabbitMQ: Admin path-traversal write via trace nameEPSS —