RabbitMQ Security
As the steward of RabbitMQ, we at Broadcom take the security of RabbitMQ very seriously.
How to Report a Vulnerability
To responsibly disclose a vulnerability:
- Navigate to the
Security and qualitytab of the relevant repository on GitHub. For example:rabbitmq/rabbitmq-serverfor the core brokerrabbitmq/rabbitmq-amqp-java-clientfor the RabbitMQ AMQP 1.0 Java clientrabbitmq/cluster-operatorfor the RabbitMQ Kubernetes cluster operator
- Click
Report a vulnerabilityto open a private advisory draft. - Provide details, including steps to reproduce.
If you are unable to use GitHub Security Advisories, you can email tnz-rabbitmq-core.pdl@broadcom.com.
Our team will review the report, triage it, and work with you to resolve the issue privately before issuing a public patch and advisory.
Please do not report security vulnerabilities via public GitHub issues, public mailing lists, or public Discord channels.
Security Advisories
For commercial Broadcom / VMware Tanzu Customers
If you are a commercial customer using VMware Tanzu RabbitMQ or other commercial distributions, please refer to the Broadcom Security Advisories.
The Broadcom Support Portal is the authoritative source of truth for all commercial releases. It includes comprehensive vulnerability information, including CVEs in dependencies and underlying Erlang runtime that are not listed on this page.
You can search the Broadcom Security Advisories for a specific RabbitMQ version. For example, if you type RabbitMQ 4.2.8 into the search box, you will see the security advisory for that specific release.
Open Source Advisories
For convenience, the table below lists all public security advisories across the RabbitMQ GitHub organization.
| Advisory ID & CVE ID | Date Published 🔽 | Severity | Repository | Summary | Affected Versions | Patched Versions |
|---|---|---|---|---|---|---|
| 2026-07-23 | Medium | rabbitmq-server | AMQP 1.0 management `GET /bindings` exposes full binding topology to any authenticated AMQP user without resource/management permission checks | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23 | ||
CVE ID pending | 2026-07-23 | High | rabbitmq-server | JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252) | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23>= 3.13.0, < 3.13.18 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Atom exhaustion: to_atom on global-parameter :name | >= 4.3.0, < 4.3.1>= 4.2.0, < 4.2.7>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.22 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Incomplete fix for CVE-2026-44838: `escape_regex_char/1` does not escape `-`, leaving room for an MQTT topic permission bypass | >= 4.3.2, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Shovel does not format state logged by the crash reporter and can leave unencrypted credentials in a crash dump file | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23 | |
CVE ID pending | 2026-07-23 | High | rabbitmq-server | OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200) | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Authenticated RabbitMQ JMS Topic Selector Users Can Consume Broker CPU with an Unbounded LIKE Regular Expression | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Shovel Management Atom Exhaustion Allows Persistent Broker-Wide Denial of Service | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | (Web) MQTT with PROXY Protocol enabled: a loopback-only user permission bypass | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.23>= 3.13.0, < 3.13.18 | |
CVE ID pending | 2026-07-23 | Medium | rabbitmq-server | Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access | >= 4.3.0, < 4.3.3>= 4.2.0, < 4.2.9>= 4.1.0, < 4.1.14>= 4.0.0, < 4.0.24>= 3.13.0, < 3.13.18 |