Product Release Advisory - Open Source RabbitMQ 4.1.2
Security Advisory
|
Advisory ID: |
TNZ-2026-0334 |
|
Severity: |
[Medium] |
|
Issue Date: |
2026-05-06 |
|
Updated on: |
2026-07-23 |
|
Synopsis |
Unsanitized virtual host names allow for XSS in the management UI pages that list virtual hosts if the attacker manages to find a way to force a virtual host to restart. CVE-2026-44839 (medium) |
Patched Versions
- Open Source RabbitMQ 4.1.2
Product Versions Affected
- Open Source RabbitMQ >= 4.1.0, < 4.1.2
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.1.0, < 4.1.2
- VMware Tanzu RabbitMQ on Kubernetes >= 4.1.0, < 4.1.2
History
2026-07-09: Initial vulnerability report published.
Contact
E-mail: [email protected]
VMware Tanzu Security Advisories