VYPR

Bitnami package

rabbitmq

pkg:bitnami/rabbitmq

Vulnerabilities (66)

  • CVE-2026-67225MedSep 25, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's declared length before buffering the frame. With t

  • CVE-2026-67223MedSep 25, 2026
    affected >= 3.13.0, < 3.13.18fixed 3.13.18

    RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username} into user_dn_pattern without RFC 4514 DN e

  • CVE-2026-67222MedSep 25, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied list_to_atom/1 to every colon-delimited token in an attacker-controlled auth_mechanism value, permanently consuming Erlang VM atoms and allowing the node to be

  • CVE-2026-66078LowSep 25, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag bypass via bulk-delete. dELETE /api/users/:name refuses to delete users tagged protected (rabbitmgmtwmuser:deleteresource/2 checks isprotecteduser). POST /api/us

  • CVE-2026-66073MedSep 25, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts a node JSON field. The value goes through

  • CVE-2026-66071MedSep 25, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercion:toatom() to convert to a tag atom. The to

  • CVE-2026-61837MedSep 25, 2026
    affected >= 4.0.0, < 4.0.23fixed 4.0.23

    RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without resource/management permission checks. the AMQP 1.0 HTTP-over-AMQP management en

  • CVE-2026-67236HigSep 25, 2026
    affected >= 4.2.0, < 4.2.8fixed 4.2.8

    RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameSite, or expiration protections. Because bas

  • CVE-2026-67233MedSep 24, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitoring tag. But allowed_methods includes DELETE

  • CVE-2026-67405MedSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl

  • CVE-2026-67404CriSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forge the JWKS response,

  • CVE-2026-67240LowSep 23, 2026
    affected >= 4.2.0, < 4.2.7fixed 4.2.7

    RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ -> ., then compiles ^...$ with only [unicode]; re:run is called with only [{capture, none}] - no explicit match_limit. A pattern like %_%_..._%X becomes ^.*?..*?.

  • CVE-2026-67235HigSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-header BodySize (a uint64) was stored without validation against max_message_size. The size check ran only when assembly completed. By declaring body_size = 2^63

  • CVE-2026-67232HigSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does not set max_frame_size, so cowboy's default

  • CVE-2026-67231CriSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The mat

  • CVE-2026-67229MedSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_vhost/2 calls rabbit_data_coercion:atomize_keys/1 (the unsafe variant using binary_to_atom) on the vhost metadata map. The 20 MB management body limit fits ~1M+ short ke

  • CVE-2026-67228MedSep 23, 2026
    affected >= 4.2.0, < 4.2.7fixed 4.2.7

    RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The runtime-parameters lookup path coerces the URL :component segment to an atom with rabbit_data_coercion:to_atom/1 in lookup_component/1 (deps/rabbit/src/rabbit_runtime_parameters.erl), creating a

  • CVE-2026-67224LowSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace consumer constructs the output path as filename:join(TraceDir, Name ++ ".log") where Name comes from PUT /api/traces/:vhost/:name. No safe_relative_path / traversa

  • CVE-2026-67221MedSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI

  • CVE-2026-67220MedSep 23, 2026
    affected >= 3.13.0, < 3.13.15fixed 3.13.15

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 reads the rjms_erlang_selector argument and passes it through erl_scan:string/1 then erl_parse:parse_term/1.