CVE Tools

Rabbitmq

22 CVEs tracked since 2026. Since Jul 2026, none of them reached CISA KEV.

Rabbitmq CVEs per month

Jul 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Rabbitmq CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-07110
2026-08null or fewer
2026-09110

Products

The products that kept showing up in Rabbitmq's monthly top three, with their CVEs summed over those months.

  1. Rabbitmq-server111 month
  2. AMQP091-GO101 month
  3. Rabbitmq-java-client11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Rabbitmq.

  1. CVE-2026-67420RabbitMQ OAuth credential refresh retains revoked runtime tags—
  2. CVE-2026-67419RabbitMQ: Consecutive topic wildcards cause combinatorial routing work—
  3. CVE-2026-67421RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling—
  4. CVE-2026-67408RabbitMQ: Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service—
  5. CVE-2026-67406RabbitMQ: Federation and Shovel Gen-Servers Lack format_status Callback — Plaintext Credentials Exposed in Crash Dumps and sys:get_status—
  6. CVE-2026-67410RabbitMQ: OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint—
  7. CVE-2026-67227RabbitMQ: Atom exhaustion: to_atom on global-parameter :name—
  8. CVE-2026-67407RabbitMQ: Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass—
  9. CVE-2026-67226RabbitMQ: Admin-only atom exhaustion: PUT /api/users tags list—
  10. CVE-2026-67411RabbitMQ: Web MQTT with PROXY Protocol enabled: a loopback-only user permission bypass—
  11. CVE-2026-67413RabbitMQ: Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression—
  12. CVE-2026-61837RabbitMQ: AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checks—
  13. CVE-2026-67415RabbitMQ: Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service—
  14. CVE-2026-67412RabbitMQ: Federation upstream skips vhost authorization allowing cross-vhost message access—
  15. CVE-2026-67409RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS—

The record

Peak rank
#112 in Sep 2026
Busiest month shown
Jul 2026, 11 CVEs
Months with a KEV entry
0 since Jul 2026
Monthly snapshots
2 since 2026
Rabbitmq's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store