VendorsBroadcomrabbitmq_serverany version
Vulnerabilities

Broadcom RabbitMQ Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2026-57216
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
Published 2026-07-10 · Analyzed
10.0EPSS 0.009
CVE-2026-57211
RabbitMQ: UNC SSRF affecting the management UI on Windows
Published 2026-07-10 · Analyzed
10.0EPSS 0.006
CVE-2026-57215
RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
Published 2026-07-10 · Analyzed
8.8EPSS 0.007
CVE-2026-57219
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Published 2026-07-10 · Analyzed
8.7EPSS 0.020
CVE-2026-44838
RabbitMQ MQTT Topic Permission Authorization Bypass
Published 2026-05-27 · Analyzed
8.1EPSS 0.004
CVE-2021-22117
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
Published 2021-05-18 · Modified
7.8EPSS 0.006
CVE-2026-57212
RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
Published 2026-07-10 · Analyzed
7.7EPSS 0.007
CVE-2019-11287
RabbitMQ Web Management Plugin DoS via heap overflow
Published 2019-11-22 · Modified
7.5EPSS 0.044
CVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Published 2026-07-10 · Analyzed
7.5EPSS 0.010
CVE-2022-31008
Predictable credential obfuscation seed value used in rabbitmq-server
Published 2022-10-06 · Modified
7.5EPSS 0.003
CVE-2026-57214
RabbitMQ: Stored XSS in RabbitMQ management UI
Published 2026-07-10 · Analyzed
7.1EPSS 0.004
CVE-2026-57217
RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
Published 2026-07-10 · Analyzed
7.0EPSS 0.006
CVE-2020-5419
RabbitMQ arbitrary code execution using local binary planting
Published 2020-08-31 · Modified
6.7EPSS 0.005
CVE-2025-50200
RabbitMQ Node can log Basic Auth header from an HTTP request
Published 2025-06-19 · Analyzed
6.7EPSS 0.002
CVE-2026-57218
RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
Published 2026-07-10 · Analyzed
6.5EPSS 0.006
CVE-2026-57213
RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
Published 2026-07-10 · Modified
5.7EPSS 0.004
CVE-2026-44839
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
Published 2026-05-27 · Analyzed
5.6EPSS 0.002
CVE-2026-57221
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
Published 2026-07-10 · Analyzed
5.3EPSS 0.005
CVE-2019-11291
RabbitMQ XSS attack via federation and shovel endpoints
Published 2019-11-22 · Modified
4.8EPSS 0.008