CVE-2026-67421
- EPSS 0.3%
- Veröffentlicht 25.09.2026 16:39:02
- Zuletzt bearbeitet 06.10.2026 19:53:05
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management...
CVE-2026-57217
- EPSS 0.35%
- Veröffentlicht 10.07.2026 20:25:29
- Zuletzt bearbeitet 13.07.2026 21:04:14
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can ...
- EPSS 0.41%
- Veröffentlicht 10.07.2026 20:24:27
- Zuletzt bearbeitet 13.07.2026 20:44:52
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can con...
CVE-2026-57215
- EPSS 0.38%
- Veröffentlicht 10.07.2026 20:23:26
- Zuletzt bearbeitet 13.07.2026 21:27:14
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are m...
CVE-2026-57219
- EPSS 0.78%
- Veröffentlicht 10.07.2026 20:22:26
- Zuletzt bearbeitet 29.07.2026 20:17:04
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing c...
CVE-2026-57218
- EPSS 0.35%
- Veröffentlicht 10.07.2026 20:21:30
- Zuletzt bearbeitet 13.07.2026 20:54:58
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not...
- EPSS 0.5%
- Veröffentlicht 10.07.2026 20:20:33
- Zuletzt bearbeitet 13.07.2026 21:09:20
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted throug...
CVE-2026-57220
- EPSS 0.55%
- Veröffentlicht 10.07.2026 20:19:23
- Zuletzt bearbeitet 13.07.2026 20:49:24
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated ...
CVE-2026-57214
- EPSS 0.22%
- Veröffentlicht 10.07.2026 20:18:15
- Zuletzt bearbeitet 13.07.2026 21:27:48
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user...
- EPSS 0.43%
- Veröffentlicht 10.07.2026 20:16:01
- Zuletzt bearbeitet 13.07.2026 22:40:24
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation whe...