Security: rabbitmq/rabbitmq-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
AMQP 1.0 symbolic body descriptor prefix collisions bypass validationGHSA-p35w-6mx2-q4pc published
Jul 23, 2026 by michaelklishinModerate -
RabbitMQ AMQP 1.0 parser: amplification memory-exhaustion DoS via zero-width array aggregationGHSA-w6mq-4qpx-v7mh published
Jul 23, 2026 by michaelklishinModerate -
Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular ExpressionGHSA-chxf-3hfg-j8f7 published
Jul 23, 2026 by michaelklishinModerate -
Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message accessGHSA-42pc-678q-v8qj published
Jul 23, 2026 by michaelklishinModerate -
(Web) MQTT with PROXY Protocol enabled: a loopback-only user permission bypassGHSA-4r6f-9cpw-f6g6 published
Jul 23, 2026 by michaelklishinModerate -
Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypassGHSA-q46v-hrvq-hp24 published
Jul 23, 2026 by michaelklishinModerate -
Shovel does not format state logged by the crash reporter and can leave unencrypted credentials in a crash dump fileGHSA-q44f-9vc5-grh7 published
Jul 23, 2026 by michaelklishinModerate -
OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200)GHSA-f9f2-q3jf-wfj3 published
Jul 23, 2026 by michaelklishinHigh -
JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252)GHSA-qw3h-qqm9-jrw8 published
Jul 23, 2026 by michaelklishinHigh -
Stream protocol skips per vhost per user connection limitsGHSA-hwqx-2gfg-89qf published
Jul 9, 2026 by ansdModerate