Product Release Advisory - Open Source RabbitMQ 4.2.6
Product Release Advisory
|
Advisory ID: |
TNZ-2026-0339 |
|
Severity: |
[Critical] |
|
Issue Date: |
2026-06-18 |
|
Updated on: |
2026-07-23 |
|
Synopsis |
Open Source RabbitMQ 4.2.6 resolves 35 security vulnerabilities: • GHSA-9wm4-9m6g-w38x (medium): Shovel DEBUG log of full state exposes decrypted URIs • GHSA-p3hp-v9wh-ghm7 (high): CORS * reflects Origin with Allow-Credentials • GHSA-89p2-f5cv-x5cg (medium): Atom exhaustion: OAuth2 JWT tag: scope values • GHSA-ggrw-qm45-hwpv (medium): Admin-only atom exhaustion: atomize_keys on vhost metadata • GHSA-c8c4-gvv4-8j3q (medium): Stream-protocol frame length never validated against frame_max • GHSA-9c4f-rxxm-88q3 (medium): CSWSH on Web-STOMP / Web-MQTT (no Origin validation) • GHSA-h7cq-qrr8-7vgc (low): Admin path-traversal write via trace name • GHSA-37wx-r6q9-6fhj (critical): OAuth2 silent verify_none fallback for JWKS fetch • GHSA-85jr-6rr2-j73r (medium): list_to_atom on auth_mechanism URI tokens in amqp_client • GHSA-x5h5-588r-cv55 (medium): AMQP 1.0 shovel status exposes plaintext URI passwords • GHSA-r3qr-4h63-mvj2 (medium): JMS topic exchange erl_scan atom exhaustion • GHSA-m8pg-4x2h-jvgr (medium): Consistent-hash exchange unbounded weight • GHSA-34jw-rm7g-hph4 (low): Super-stream HTTP creation skips configure-permission check • GHSA-wg79-5449-m728 (medium): Super-stream partitions unbounded allocation • GHSA-7v63-j4gm-p4rh (medium): Web-STOMP unbounded pre-auth accumulation • GHSA-cw8c-4m83-9c6w (critical): Trust-store whitelist by Issuer+Serial only • GHSA-gmgx-hhg5-43gr (high): Web-MQTT decompression bomb • GHSA-c66h-hf5j-8jf9 (high): Pre-auth AMQP 1.0 array32 zero-width element DoS • GHSA-j9m2-hw6x-rqr9 (low): protected tag bypass via bulk-delete • GHSA-rjcf-35r5-xw38 (high): Stored XSS via TLS peer-certificate DN in management UI • GHSA-j45q-v7g2-82ph (low): Cross-vhost quorum-queue status and stream tracking disclosure • GHSA-g5v3-w5xg-62q2 (low): Monitoring-tag user can restart federation links • GHSA-7jc3-73v6-rjvc (medium): Monitoring-tag user can DELETE shovels • GHSA-rg5q-vcgf-rfh7 (medium): ReDoS via management API ?name= filter • GHSA-q8g2-pc7m-m3jw (high): AMQP 0-9-1 body assembly never validates accumulated size • GHSA-6v53-r759-jrvx (medium): Atom table exhaustion via management API node field • GHSA-48hm-chgv-398r (medium): Atom table exhaustion via stream `chunk_selector` • CVE-2026-57219 (high): Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations • CVE-2026-57221 (medium): Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users • CVE-2026-57220 (high): Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS • CVE-2026-57218 (medium): AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure • CVE-2026-57217 (high): Topic authorization can lead to cross-tenant routing-key bypass • CVE-2026-57216 (medium): AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks • CVE-2026-57215 (high): Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom • CVE-2026-57211 (medium): UNC SSRF affecting RabbitMQ management UI on Windows https://nvd.nist.gov/vuln/detail/CVE-2026-57219 https://nvd.nist.gov/vuln/detail/CVE-2026-57221 https://nvd.nist.gov/vuln/detail/CVE-2026-57220 https://nvd.nist.gov/vuln/detail/CVE-2026-57218 https://nvd.nist.gov/vuln/detail/CVE-2026-57217 https://nvd.nist.gov/vuln/detail/CVE-2026-57216 |
Product Version Release Advisory
- Open Source RabbitMQ 4.2.6
Security Fixes
This release has the following security fixes, listed by component and area.
|
Component |
Vulnerabilities Resolved |
|
Shovel Plugin |
GHSA-9wm4-9m6g-w38x (medium) |
|
Core |
GHSA-p3hp-v9wh-ghm7 (high) |
|
OAuth2 Plugin |
GHSA-89p2-f5cv-x5cg (medium) |
|
Core |
GHSA-ggrw-qm45-hwpv (medium) |
|
Stream Plugin |
GHSA-c8c4-gvv4-8j3q (medium) |
|
MQTT Plugin |
GHSA-9c4f-rxxm-88q3 (medium) |
|
Core |
GHSA-h7cq-qrr8-7vgc (low) |
|
OAuth2 Plugin |
GHSA-37wx-r6q9-6fhj (critical) |
|
Core |
GHSA-85jr-6rr2-j73r (medium) |
|
Shovel Plugin |
GHSA-x5h5-588r-cv55 (medium) |
|
Core |
GHSA-r3qr-4h63-mvj2 (medium) |
|
Core |
GHSA-m8pg-4x2h-jvgr (medium) |
|
Stream Plugin |
GHSA-34jw-rm7g-hph4 (low) |
|
Stream Plugin |
GHSA-wg79-5449-m728 (medium) |
|
STOMP Plugin |
GHSA-7v63-j4gm-p4rh (medium) |
|
Core |
GHSA-cw8c-4m83-9c6w (critical) |
|
MQTT Plugin |
GHSA-gmgx-hhg5-43gr (high) |
|
AMQP 1.0 Plugin |
GHSA-c66h-hf5j-8jf9 (high) |
|
Core |
GHSA-j9m2-hw6x-rqr9 (low) |
|
Management Plugin |
GHSA-rjcf-35r5-xw38 (high) |
|
Stream Plugin |
GHSA-j45q-v7g2-82ph (low) |
|
Federation Plugin |
GHSA-g5v3-w5xg-62q2 (low) |
|
Shovel Plugin |
GHSA-7jc3-73v6-rjvc (medium) |
|
Management Plugin |
GHSA-rg5q-vcgf-rfh7 (medium) |
|
Core |
GHSA-q8g2-pc7m-m3jw (high) |
|
Management Plugin |
GHSA-6v53-r759-jrvx (medium) |
|
Stream Plugin |
GHSA-48hm-chgv-398r (medium) |
|
Management Plugin |
|
|
Core |
|
|
Stream Plugin |
|
|
OAuth2 Plugin |
|
|
Core |
|
|
Stream Plugin |
|
|
Core |
|
|
Management Plugin |
Product Versions Affected
- Open Source RabbitMQ >= 4.2.0, < 4.2.6
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.2.0, < 4.2.6
- VMware Tanzu RabbitMQ on Kubernetes >= 4.2.0, < 4.2.6
History
2026-07-14: Initial vulnerability report published.
Contact
E-mail: [email protected]
VMware Tanzu Security Advisories