VendorsBroadcomrabbitmq_serverall versions
Vulnerabilities

Broadcom RabbitMQ Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2026-57216
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Published 2026-07-10 · Analyzed
10.0EPSS 0.009
CVE-2026-57211
RabbitMQ: UNC SSRF affecting the management UI on Windows
Published 2026-07-10 · Analyzed
10.0EPSS 0.006
CVE-2016-9877
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Published 2016-12-29 · Modified
9.8EPSS 0.014
CVE-2026-57215
RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Published 2026-07-10 · Analyzed
8.8EPSS 0.007
CVE-2026-57219
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Published 2026-07-10 · Analyzed
8.7EPSS 0.020
CVE-2026-44838
RabbitMQ MQTT Topic Permission Authorization Bypass
Published 2026-05-27 · Analyzed
8.1EPSS 0.003
CVE-2021-22117
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
Published 2021-05-18 · Modified
7.8EPSS 0.006
CVE-2017-4966
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack.
Published 2017-06-13 · Modified
7.8EPSS 0.004
CVE-2026-57212
RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
Published 2026-07-10 · Analyzed
7.7EPSS 0.007
CVE-2019-11287
RabbitMQ Web Management Plugin DoS via heap overflow
Published 2019-11-22 · Modified
7.5EPSS 0.044
CVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Published 2026-07-10 · Analyzed
7.5EPSS 0.010
CVE-2022-31008
Predictable credential obfuscation seed value used in rabbitmq-server
Published 2022-10-06 · Modified
7.5EPSS 0.003
CVE-2026-57214
RabbitMQ: Stored XSS in RabbitMQ management UI
Published 2026-07-10 · Analyzed
7.1EPSS 0.004
CVE-2026-57217
RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Published 2026-07-10 · Analyzed
7.0EPSS 0.006
CVE-2020-5419
RabbitMQ arbitrary code execution using local binary planting
Published 2020-08-31 · Modified
6.7EPSS 0.005
CVE-2025-50200
RabbitMQ Node can log Basic Auth header from an HTTP request
Published 2025-06-19 · Analyzed
6.7EPSS 0.002
CVE-2026-57218
RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
Published 2026-07-10 · Analyzed
6.5EPSS 0.006
CVE-2017-4965
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Published 2017-06-13 · Modified
6.1EPSS 0.033
CVE-2017-4967
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Published 2017-06-13 · Modified
6.1EPSS 0.019
CVE-2026-57213
RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Published 2026-07-10 · Modified
5.7EPSS 0.004
CVE-2026-44839
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
Published 2026-05-27 · Analyzed
5.6EPSS 0.002
CVE-2026-57221
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
Published 2026-07-10 · Analyzed
5.3EPSS 0.005
CVE-2014-9650
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
Published 2015-01-27 · Modified
5.0EPSS 0.026
CVE-2019-11291
RabbitMQ XSS attack via federation and shovel endpoints
Published 2019-11-22 · Modified
4.8EPSS 0.008
CVE-2014-9649
Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
Published 2015-01-27 · Modified
4.3EPSS 0.023