OESA-2026-4032

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4032
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4032.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4032
Upstream
CVE (11)
Published
2026-09-25T01:27:30Z
Modified
2026-09-25T01:45:06Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
rabbitmq-server security update
Details

RabbitMQ is an implementation of AMQP, the emerging standard for high performance enterprise messaging. The RabbitMQ server is a robust and scalable implementation of an AMQP broker.

Security Fix(es):

RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.(CVE-2023-46118)

RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails to start, recent versions will display an error message (a notification) in the management UI. The error message includes virtual host name, which was not escaped prior to open source RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3, 3.13.8. An attack that both makes a virtual host fail to start and creates a new virtual host name with an XSS code snippet or changes the name of an existing virtual host on disk could trigger arbitrary JavaScript code execution in the management UI (the user's browser). Open source RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3 and 3.13.8 patch the issue.(CVE-2025-30219)

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.(CVE-2026-44839)

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.(CVE-2026-57212)

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.(CVE-2026-57213)

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.(CVE-2026-57214)

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.(CVE-2026-57215)

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.(CVE-2026-57216)

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.(CVE-2026-57221)

An authenticated tenant that is allowed to bind and publish to an x-jms-topic exchange can repeatedly consume RabbitMQ scheduler CPU while messages are routed. This delays publisher confirms and competes with unrelated broker work on the same node. The attacker can amplify the effect by publishing more messages or using multiple bindings, channels, or connections. The issue does not provide message disclosure, privilege escalation, or code execution. Its demonstrated impact is availability degradation. The reproduction establishes substantial per-message CPU amplification but does not claim that a single test connection alone causes a complete node outage.(CVE-2026-67409)

An authenticated tenant that is allowed to bind and publish to an x-jms-topic exchange can repeatedly consume RabbitMQ scheduler CPU while messages are routed. This delays publisher confirms and competes with unrelated broker work on the same node. The attacker can amplify the effect by publishing more messages or using multiple bindings, channels, or connections.

The issue does not provide message disclosure, privilege escalation, or code execution. Its demonstrated impact is availability degradation. The reproduction establishes substantial per-message CPU amplification but does not claim that a single test connection alone causes a complete node outage.(CVE-2026-67413)

Database specific
{
    "severity":  "High"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:rpm/openEuler/rabbitmq-server&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.9.23-4.oe2403sp3

Ecosystem specific

{
    "aarch64":  [
        "rabbitmq-server-3.9.23-4.oe2403sp3.aarch64.rpm"
    ],
    "src":  [
        "rabbitmq-server-3.9.23-4.oe2403sp3.src.rpm"
    ],
    "x86_64":  [
        "rabbitmq-server-3.9.23-4.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4032.json"