[WID-SEC-2026-2485] RabbitMQ: Mehrere Schwachstellen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 22.07.2026 Stand 23.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung RabbitMQ ist ein Open-Source Message Broker. Produkte 22.07.2026 Open Source RabbitMQ <4.3.3 Open Source RabbitMQ <4.2.9 Open Source RabbitMQ <4.1.14 Open Source RabbitMQ <4.0.24 Open Source RabbitMQ <3.13.18 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in RabbitMQ ausnutzen, um Denial-of-Service-Angriffe durchzuführen, Autorisierungs- und Mandantengrenzen zu umgehen, Daten zu manipulieren oder offenzulegen und Cross Site Scripting Angriffe durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in RabbitMQ (CVSS Base Score 7.5) allow a remote, anonymous attacker to cause Denial-of-Service, bypass authorization and tenant boundaries, manipulate or expose data, and perform Cross-Site Scripting attacks. Affected versions include RabbitMQ open-source versions prior to 4.3.3, 4.2.9, 4.1.14, 4.0.24, and 3.13.18. A mitigation is available, though the specific patch or workaround details are not provided in the advisory.