Rabbitmq
22 CVEs tracked since 2026. Since Jul 2026, none of them reached CISA KEV.
Rabbitmq CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-07 | 11 | 0 |
| 2026-08 | null or fewer | |
| 2026-09 | 11 | 0 |
Products
The products that kept showing up in Rabbitmq's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Rabbitmq.
- CVE-2026-67420RabbitMQ OAuth credential refresh retains revoked runtime tags—
- CVE-2026-67419RabbitMQ: Consecutive topic wildcards cause combinatorial routing work—
- CVE-2026-67421RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling—
- CVE-2026-67408RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service—
- CVE-2026-67406RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_status—
- CVE-2026-67410RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint—
- CVE-2026-67227RabbitMQ: Atom exhaustion: to_atom on global-parameter :name—
- CVE-2026-67407RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass—
- CVE-2026-67226RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list—
- CVE-2026-67411RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass—
- CVE-2026-67413RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression—
- CVE-2026-61837RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checks—
- CVE-2026-67415RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service—
- CVE-2026-67412RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access—
- CVE-2026-67409RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS—
The record
- Peak rank
- #112 in Sep 2026
- Busiest month shown
- Jul 2026, 11 CVEs
- Months with a KEV entry
- 0 since Jul 2026
- Monthly snapshots
- 2 since 2026