Security: rabbitmq/rabbitmq-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Atom exhaustion: to_atom on runtime-parameter componentGHSA-73qp-fwh4-2q5g published
Jul 9, 2026 by ansdModerate -
Atom exhaustion: to_atom on global-parameter :nameGHSA-q7x8-97rh-cr24 published
Jul 23, 2026 by michaelklishinModerate -
Admin-only atom exhaustion: PUT /api/users tags listGHSA-34c7-r8w9-5wv8 published
Jul 23, 2026 by michaelklishinModerate -
Stream-protocol frame length never validated against frame_maxGHSA-c8c4-gvv4-8j3q published
Jul 9, 2026 by ansdModerate -
CSWSH on Web-STOMP / Web-MQTT (no Origin validation)GHSA-9c4f-rxxm-88q3 published
Jul 9, 2026 by ansdModerate -
Admin path-traversal write via trace nameGHSA-h7cq-qrr8-7vgc published
Jul 9, 2026 by ansdLow -
LDAP DN injection via unescaped substitutionGHSA-9x7r-g78c-5835 published
Jul 22, 2026 by michaelklishinModerate -
OAuth2 silent verify_none fallback for JWKS fetchGHSA-37wx-r6q9-6fhj published
Jul 9, 2026 by ansdCritical -
list_to_atom on auth_mechanism URI tokens in amqp_clientGHSA-85jr-6rr2-j73r published
Jul 9, 2026 by ansdModerate -
AMQP 1.0 shovel status exposes plaintext URI passwordsGHSA-x5h5-588r-cv55 published
Jul 9, 2026 by ansdModerate