Product Release Advisory - Open Source RabbitMQ 4.2.5
Product Release Advisory
|
Advisory ID: |
TNZ-2026-0338 |
|
Severity: |
[High] |
|
Issue Date: |
2026-06-18 |
|
Updated on: |
2026-07-02 |
|
Synopsis |
Open Source RabbitMQ 4.2.5 resolves 3 security vulnerabilities: • CVE-2026-57212 (high): RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size • CVE-2026-57213 (medium): Stored XSS in RabbitMQ federation management plugin via unsanitized consumer_tag rendering • CVE-2026-57214 (high): Stored XSS in RabbitMQ management UI https://nvd.nist.gov/vuln/detail/CVE-2026-57212 |
Product Version Release Advisory
- Open Source RabbitMQ 4.2.5
Security Fixes
This release has the following security fixes, listed by component and area.
|
Component |
Vulnerabilities Resolved |
|
Management Plugin |
|
|
Management Plugin |
|
|
Management Plugin |
Product Versions Affected
- Open Source RabbitMQ >= 4.2.0, < 4.2.5
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.2.0, < 4.2.5
- VMware Tanzu RabbitMQ on Kubernetes >= 4.2.0, < 4.2.5
- VMware Tanzu RabbitMQ on Tanzu Platform >= 4.2.0, < 4.2.5
History
2026-07-09: Initial vulnerability report published.
Contact
E-mail: [email protected]
VMware Tanzu Security Advisories