openSUSE-SU-2026:21903-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21903-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21903-1
Upstream
CVE (11)
Related
Published
2026-09-22T02:16:57Z
Modified
2026-09-25T18:23:12Z
Summary
Security update for rabbitmq-server
Details

This update for rabbitmq-server fixes the following issues:

  • CVE-2026-44839: XSS in management UI due to unsanitized vhost names (bsc#1266465).
  • CVE-2026-57212: The rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths (bsc#1271318).
  • CVE-2026-57213: stored XSS in RabbitMQ federation management plugin via unsanitized consumer_tag rendering (bsc#1271336).
  • CVE-2026-57214: stored XSS in RabbitMQ management UI (bsc#1271337).
  • CVE-2026-57215: direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom (bsc#1271338).
  • CVE-2026-57216: stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks (bsc#1271339).
  • CVE-2026-57217: topic authorization can lead to cross-tenant routing-key bypass (bsc#1271340).
  • CVE-2026-57218: consumer persistence can lead to post-revocation message disclosure in OAuth2 (bsc#1271343).
  • CVE-2026-57219: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations (bsc#1271344).
  • CVE-2026-57220: stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS (bsc#1271345).
  • CVE-2026-57221: passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users (bsc#1271346).
References

Affected packages

openSUSE:Leap 16.0 / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:rpm/opensuse/rabbitmq-server&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.5-160000.2.1

Ecosystem specific

{
    "binaries":  [
        {
            "erlang-rabbitmq-client":  "4.1.5-160000.2.1",
            "rabbitmq-server":  "4.1.5-160000.2.1",
            "rabbitmq-server-bash-completion":  "4.1.5-160000.2.1",
            "rabbitmq-server-plugins":  "4.1.5-160000.2.1",
            "rabbitmq-server-zsh-completion":  "4.1.5-160000.2.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21903-1.json"