VYPR

Vendor CVEs

Rabbitmq

All CVEs

106 total · sorted by risk
  • CVE-2026-67218LowSep 23, 2026
    risk 0.07cvss —epss 0.00

    RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which only checks the management tag + vhost access via…

  • CVE-2026-61634NonAug 18, 2026
    risk 0.00cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java…

  • CVE-2023-35789MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

  • CVE-2014-9650Jan 27, 2015
    risk 0.00cvss —epss 0.03

    CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

  • CVE-2014-9649Jan 27, 2015
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.

  • CVE-2014-9494Jan 20, 2015
    risk 0.00cvss —epss 0.01

    RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.

Page 3 of 3