Rabbitmq Server
26 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Rabbitmq Server, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Rabbitmq Server CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 11 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 26 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High8
- Medium17
Latest CVEs
The 15 most recently published vulnerabilities affecting Rabbitmq Server.
- CVE-2026-57217RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass6.5
- CVE-2026-57221RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users5.0
- CVE-2026-57215RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom8.8
- CVE-2026-57219RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations7.5
- CVE-2026-57218RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure6.5
- CVE-2026-57216RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks6.8
- CVE-2026-57220RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS7.5
- CVE-2026-57214RabbitMQ: Stored XSS in RabbitMQ management UI5.4
- CVE-2026-57211RabbitMQ: UNC SSRF affecting the management UI on Windows6.5
- CVE-2026-57212RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size7.7
- CVE-2026-57213RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering4.8
- CVE-2026-44839RabbitMQ: Unsanitized vhost names allow for XSS in management UI4.8
- CVE-2026-44838RabbitMQ MQTT Topic Permission Authorization Bypass8.1
- CVE-2025-50200RabbitMQ Node can log Basic Auth header from an HTTP request5.5
- CVE-2022-31008Predictable credential obfuscation seed value used in rabbitmq-server5.5
Product grouping is registry-driven, with AI assist and human review. How it works