Product Release Advisory - Open Source RabbitMQ 4.0.13
Security Advisory
|
Advisory ID: |
TNZ-2026-0330 |
|
Severity: |
[Medium] |
|
Issue Date: |
2026-05-06 |
|
Updated on: |
2026-07-23 |
|
Synopsis |
Unsanitized virtual host names allow for XSS in the the management UI pages that list virtual hosts if the attacker manages to find a way to force a virtual host to restart. CVE-2026-44839 (medium) |
Patched Versions
- Open Source RabbitMQ 4.0.13
Product Versions Affected
- Open Source RabbitMQ >= 4.0.0, < 4.0.13
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.0.0, < 4.0.13
- VMware Tanzu RabbitMQ on Kubernetes >= 4.0.0, < 4.0.13
History
2026-07-02: Initial vulnerability report published.
Contact
E-mail: [email protected]
VMware Tanzu Security Advisories
https://tanzu.vmware.com/security