Broadcom

Rabbitmq Server

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 25.09.2026 16:39:02
  • Zuletzt bearbeitet 06.10.2026 19:53:05

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.07.2026 20:25:29
  • Zuletzt bearbeitet 13.07.2026 21:04:14

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can ...

Medienbericht Exploit
  • EPSS 0.41%
  • Veröffentlicht 10.07.2026 20:24:27
  • Zuletzt bearbeitet 13.07.2026 20:44:52

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can con...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 10.07.2026 20:23:26
  • Zuletzt bearbeitet 13.07.2026 21:27:14

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are m...

Medienbericht
  • EPSS 0.78%
  • Veröffentlicht 10.07.2026 20:22:26
  • Zuletzt bearbeitet 29.07.2026 20:17:04

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing c...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.07.2026 20:21:30
  • Zuletzt bearbeitet 13.07.2026 20:54:58

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 10.07.2026 20:20:33
  • Zuletzt bearbeitet 13.07.2026 21:09:20

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted throug...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 10.07.2026 20:19:23
  • Zuletzt bearbeitet 13.07.2026 20:49:24

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated ...

  • EPSS 0.22%
  • Veröffentlicht 10.07.2026 20:18:15
  • Zuletzt bearbeitet 13.07.2026 21:27:48

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 10.07.2026 20:16:01
  • Zuletzt bearbeitet 13.07.2026 22:40:24

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation whe...