Product Release Advisory - Open Source RabbitMQ 4.0.24
|
Advisory ID: |
TNZ-2026-0382 |
|
Severity: |
[High] |
|
Issue Date: |
09-04-2026 |
|
Updated on: |
|
|
Synopsis |
Open Source RabbitMQ 4.0.24 resolves 10 security vulnerabilities:
https://nvd.nist.gov/vuln/detail/CVE-2026-67421 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6gmw-wxch-cvvc https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6xpg-rfmh-grhq https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-3526-xvv4-q9mr https://nvd.nist.gov/vuln/detail/CVE-2026-67416 https://nvd.nist.gov/vuln/detail/CVE-2026-67414 https://nvd.nist.gov/vuln/detail/CVE-2026-67412 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-27gv-h5q6-cpwg |
Product Version Release Advisory
- Open Source RabbitMQ 4.0.24
Security Fixes
This release has the following security fixes, listed by component and area.
|
Component |
Vulnerabilities Resolved |
|
Management Plugin (OAuth2 UI) |
CVE-2026-67421 (medium) |
|
Shovel Management Plugin |
GHSA-6gmw-wxch-cvvc (medium) |
|
STOMP Plugin |
GHSA-6xpg-rfmh-grhq (medium) |
|
Core (Erlang distribution) |
GHSA-3526-xvv4-q9mr (medium) |
|
Core (AMQP 1.0) |
CVE-2026-67416 (medium) |
|
Core (AMQP 1.0) |
CVE-2026-67414 (medium) |
|
Federation Plugin |
CVE-2026-67412 (medium) |
|
Federation Management Plugin |
GHSA-27gv-h5q6-cpwg (low) |
|
MQTT Plugin |
CVE-2026-67418 (low) |
|
OAuth2 Plugin |
CVE-2026-67420 (low) |
Product Versions Affected
- Open Source RabbitMQ >= 4.0.0, < 4.0.24
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.0.0, < 4.0.24
- VMware Tanzu RabbitMQ on Kubernetes >= 4.0.0, < 4.0.24