Vulnerabilidades em rabbitmq

65 resultados
Análise Vexday

RabbitMQ acumula 21 vulnerabilidades conhecidas na base Vexday, com destaque preocupante: 13 foram publicadas nos últimos 90 dias, sinalizando descobertas recentes e potencial de exploração. Nenhuma está em ataque ativo documentado (KEV), mas a ausência de críticas CVSS não reduz o risco, visto que a fraqueza dominante (CWE-863 — verificação inadequada de autorização) afeta componentes de acesso e controle. O ritmo acelerado de divulgações recentes recomenda priorização de patches e auditoria de permissões nas implementações.

CVE-2026-67238HIGHRabbitMQ: Atom-table exhaustion via reply-to queue name decodingEPSS 0.3%CVE-2026-66079HIGHRabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoSEPSS 0.3%CVE-2026-63336MEDIUMRabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITMEPSS 0.3%CVE-2026-66077HIGHRabbitMQ: Stored XSS via TLS peer-certificate DN in management UIEPSS 0.3%CVE-2026-67220MEDIUMRabbitMQ: JMS topic exchange erl_scan atom exhaustionEPSS 0.3%CVE-2026-77405CRITICALRabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI ParserEPSS 0.3%CVE-2026-66080MEDIUMRabbitMQ: Super-stream partitions unbounded allocationEPSS 0.3%CVE-2026-67228MEDIUMRabbitMQ: Atom exhaustion: to_atom on runtime-parameter componentEPSS 0.3%CVE-2026-67229MEDIUMRabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadataEPSS 0.3%CVE-2026-66076LOWRabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosureEPSS 0.3%CVE-2026-67240LOWRabbitMQ: ReDoS via AMQP 1.0 SQL filter LIKE wildcardEPSS 0.3%CVE-2026-67235HIGHRabbitMQ: AMQP 0-9-1 body assembly never validates accumulated sizeEPSS 0.3%CVE-2026-67219MEDIUMRabbitMQ: Consistent-hash exchange unbounded weightEPSS 0.3%CVE-2026-67231CRITICALRabbitMQ: Trust-store whitelist by Issuer+Serial onlyEPSS 0.2%CVE-2026-67404CRITICALRabbitMQ: OAuth2 silent verify_none fallback for JWKS fetchEPSS 0.2%CVE-2026-66075LOWRabbitMQ: Monitoring-tag user can restart federation linksEPSS 0.2%CVE-2026-44839MEDIUMRabbitMQ: Unsanitized vhost names allow for XSS in management UIEPSS 0.2%CVE-2025-50200MEDIUMRabbitMQ Node can log Basic Auth header from an HTTP requestEPSS 0.2%CVE-2025-30219MEDIUMRabbitMQ has XSS Vulnerability in an Error Message in Management UIEPSS 0.2%CVE-2026-67221MEDIUMRabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwordsEPSS 0.2%