Skip to main content

RabbitMQ Security

As the steward of RabbitMQ, we at Broadcom take the security of RabbitMQ very seriously.

How to Report a Vulnerability​

To responsibly disclose a vulnerability:

  1. Navigate to the Security and quality tab of the relevant repository on GitHub. For example:
  2. Click Report a vulnerability to open a private advisory draft.
  3. Provide details, including steps to reproduce.

If you are unable to use GitHub Security Advisories, you can email tnz-rabbitmq-core.pdl@broadcom.com.

Our team will review the report, triage it, and work with you to resolve the issue privately before issuing a public patch and advisory.

Please do not report security vulnerabilities via public GitHub issues, public mailing lists, or public Discord channels.

Security Advisories​

For commercial Broadcom / VMware Tanzu Customers​

If you are a commercial customer using VMware Tanzu RabbitMQ or other commercial distributions, please refer to the Broadcom Security Advisories.

The Broadcom Support Portal is the authoritative source of truth for all commercial releases. It includes comprehensive vulnerability information, including CVEs in dependencies and underlying Erlang runtime that are not listed on this page.

tip

You can search the Broadcom Security Advisories for a specific RabbitMQ version. For example, if you type RabbitMQ 4.2.8 into the search box, you will see the security advisory for that specific release.

Open Source Advisories​

For convenience, the table below lists all public security advisories across the RabbitMQ GitHub organization.

Advisory ID & CVE IDDate Published 🔽SeverityRepositorySummaryAffected VersionsPatched Versions
CVE ID pending
2026-09-18Mediumrabbitmq-serverRabbitMQ STOMP consumers retain OAuth queue access after JWT expiration
>= 4.3.0, < 4.3.6>= 4.2.0, < 4.2.11
CVE ID pending
2026-09-18Lowrabbitmq-serverRabbitMQ Stream Publisher Management API Discloses Unauthorized Vhost and Stream Existence
>= 4.3.0, < 4.3.6>= 4.2.0, < 4.2.11
CVE ID pending
2026-09-18Mediumrabbitmq-serverMQTT retained message store has no size or count limit and is never reclaimed
>= 4.3.0, < 4.3.5
CVE ID pending
2026-09-18Lowrabbitmq-serverCross-vhost Stream consumer virtual-host existence disclosure
>= 4.3.0, < 4.3.6>= 4.2.0, < 4.2.11
CVE ID pending
2026-09-17Mediumrabbitmq-java-clientMalformed UTF-8 in shortstr properties permanently disables RPC consumers
<= 5.35.0
5.36.0
CVE ID pending
2026-08-21Mediumrabbitmq-java-clientRabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()
<= 5.34.0
5.35.0
CVE ID pending
2026-08-18Lowrabbitmq-serverRabbitMQ consistent-hash exchange: empty array crashes DLX queue processes
>= 4.3.0, < 4.3.5>= 4.2.0, < 4.2.10
2026-08-18Lowrabbitmq-serverMQTT 5.0: inapplicable PUBLISH property disconnects matching subscribers
>= 4.3.0, < 4.3.5>= 4.2.0, < 4.2.10>= 4.1.0, < 4.1.15>= 4.0.0, < 4.0.24>= 3.13.0, < 3.13.19
2026-08-18Highrabbitmq-serverConsecutive topic wildcards cause combinatorial routing work
>= 4.3.0, < 4.3.5
CVE ID pending
2026-08-18Highrabbitmq-serverRabbitMQ Web STOMP: compressed pre-authentication messages exhaust broker memory
>= 4.3.0, < 4.3.5>= 4.2.0, < 4.2.10
Showing 1 to 10 of 114 advisories
Page 1 of 12