Broadcom
Broadcom Rabbitmq Server: vulnerabilidades y CVE
Broadcom Rabbitmq Server tiene 25 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses13
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57221 | Media (5.3) | 0.41% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any… |
| CVE-2026-57220 | Alta (7.5) | 0.55% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune… |
| CVE-2026-57219 | Alta (8.7) | 2.8% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with… |
| CVE-2026-57218 | Media (4.9) | 0.35% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes… |
| CVE-2026-57217 | Alta (7) | 0.35% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission… |
| CVE-2026-57216 | Crítica (10) | 0.50% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely… |
| CVE-2026-57215 | Alta (7) | 0.38% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted… |
| CVE-2026-57214 | Alta (7.1) | 0.22% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and… |
| CVE-2026-57213 | Media (5.7) | 0.25% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping,… |
| CVE-2026-57212 | Alta (7.1) | 0.43% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because… |
| CVE-2026-57211 | Crítica (10) | 0.63% | — | 10 jul 2026 | RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to… |
| CVE-2026-44839 | Media (5.6) | 0.18% | — | 27 may 2026 | RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13. |
| CVE-2026-44838 | Media (5.3) | 0.20% | — | 27 may 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create… |
| CVE-2025-50200 | Media (6.7) | 0.21% | — | 19 jun 2025 | RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it… |
| CVE-2022-31008 | Alta (7.5) | 0.34% | — | 6 oct 2022 | RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was… |
| CVE-2021-22117 | Alta (7.8) | 0.61% | — | 18 may 2021 | RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. |
| CVE-2020-5419 | Media (6.7) | 0.45% | — | 31 ago 2020 | RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation… |
| CVE-2019-11287 | Alta (7.5) | 4.4% | — | 23 nov 2019 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is… |
| CVE-2019-11291 | Media (4.8) | 0.80% | — | 22 nov 2019 | Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel,… |
| CVE-2017-4967 | Media (6.1) | 1.9% | — | 13 jun 2017 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to… |
| CVE-2017-4966 | Alta (7.8) | 0.37% | — | 13 jun 2017 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to… |
| CVE-2017-4965 | Media (6.1) | 3.3% | — | 13 jun 2017 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to… |
| CVE-2016-9877 | Crítica (9.8) | 1.4% | — | 29 dic 2016 | An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection… |
| CVE-2014-9650 | Media (5) | 2.6% | — | 27 ene 2015 | CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download… |
| CVE-2014-9649 | Media (4.3) | 2.3% | — | 27 ene 2015 | Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not… |
Otros productos de Broadcom
Fabric Operating System · 95Brocade Sannav · 54Tcpreplay · 52Brightstor Arcserve Backup · 41Brocade Fabric Operating System Firmware · 26Raid Controller WEB Interface · 22Sannav · 20Brightstor Enterprise Backup · 19Advanced Secure Gateway · 16Business Protection Suite · 16Etrust Antivirus · 16Etrust Intrusion Detection · 16