Medium severity5.4NVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026
CVE-2026-57214
CVE-2026-57214
Description
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.
Affected products
4- cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*Range: >=4.2.0,<4.2.5
- Range: <4.2.5
- Range: <4.2.5
- Range: <4.2.5
Patches
Vulnerability mechanics
References
6- github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2nvdPatch
- github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ecnvdPatch
- github.com/rabbitmq/rabbitmq-server/pull/15606nvdIssue TrackingPatch
- github.com/rabbitmq/rabbitmq-server/pull/15608nvdIssue TrackingPatch
- github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwpnvdVendor Advisory
- github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5nvdRelease Notes
News mentions
1- RabbitMQ: Nine Vulnerabilities Disclosed Together, Threatening Authentication and Data IntegrityVypr Intelligence · Jul 18, 2026