Search CVE reports


Toggle filters

91 – 100 of 50227 results

Status is adjusted based on your filters.


CVE-2026-67410

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67409

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252). the JWKS key...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67408

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service. rabbitMQ 4.3.1...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67407

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23, Incomplete fix for CVE-2026-44838: escaperegexchar/1 does not escape -, leaving room for an MQTT topic permission bypass. the...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67406

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, Shovel does not format state logged by the crash reporter and can leave unencrypted credentials in a crash dump file. the shovel...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67242

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-expiry checks for float exp. validatetokenexpiry/1 (lines 208-214) and expirytimestamp/1 (138-144) both guard...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67241

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare skips alternate-exchange permission check. pUT /exchanges/:name (lines 192-240) checks only configure on the...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67239

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67237

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping,...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67236

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly,...

1 affected package

rabbitmq-server

Package 20.04 LTS
rabbitmq-server Needs evaluation
Show less packages