Back to search

Broadcom

RabbitMQ

Open-source message and streaming broker supporting multiple messaging protocols.

Current version
Last checked: 2026-09-04

4.2.9

Release date
July 20, 2026
Security status
6 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

GitHub API

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
4.2.9 2026-07-20 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-57217 HIGH (7.0) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

Affected versions
  • >= 4.2.0, < 4.2.6
  • >= 4.1.0, < 4.1.11
Show 2 more
  • >= 4.0.0, < 4.0.21
  • >= 3.13.0, < 3.13.15
CVE-2026-57215 HIGH (7.0) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected versions
  • >= 4.2.0, < 4.2.6
  • >= 4.1.0, < 4.1.11
Show 2 more
  • >= 4.0.0, < 4.0.21
  • >= 3.13.0, < 3.13.15
CVE-2026-57219 HIGH (8.7) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected versions
  • >= 4.2.0, < 4.2.6
  • >= 4.1.0, < 4.1.11
Show 2 more
  • >= 4.0.0, < 4.0.21
  • >= 3.13.0, < 3.13.15
CVE-2026-57220 HIGH (7.5) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configured stream frame-size limit while assembling frames during authentication and before Tune negotiation, allowing an unauthenticated remote client to declare oversized frame lengths and consume broker memory in rabbit_stream_core. This issue is fixed in version 4.2.6.

Affected versions
  • >= 4.2.0, < 4.2.6
CVE-2026-57214 HIGH (7.1) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

Affected versions
  • >= 4.2.0, < 4.2.5
CVE-2026-57212 HIGH (7.1) 2026-07-10 Current versionnot affected

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

Affected versions
  • >= 4.2.0, < 4.2.5
  • >= 4.1.0, < 4.1.10
Show 2 more
  • >= 4.0.0, < 4.0.19
  • >= 3.13.0, < 3.13.14