Product Release Advisory - Open Source RabbitMQ 4.2.10
|
Advisory ID: |
TNZ-2026-0384 |
|
Severity: |
[High] |
|
Issue Date: |
09-04-2026 |
|
Updated on: |
|
|
Synopsis |
Open Source RabbitMQ 4.2.10 resolves 13 security vulnerabilities: GHSA-cfqc-c682-93mm (high, CVE pending): Web STOMP compressed pre-authentication messages exhaust broker memory CVE-2026-67421 (medium): Stored HTML injection in RabbitMQ Management OAuth error handling GHSA-6gmw-wxch-cvvc (medium, CVE pending): Shovel URI credentials disclosed to read-only monitoring users via the shovel management HTTP API GHSA-6xpg-rfmh-grhq (medium, CVE pending): STOMP pre-authentication frame size limit is not enforced GHSA-3526-xvv4-q9mr (medium, CVE pending): RabbitMQ administrator RCE through reflected Erlang distribution authentication GHSA-6chv-gv3h-cvcj (medium, CVE pending): Direct reply-to forged suffix fanout causes quadratic mailbox memory CVE-2026-67416 (medium): AMQP 1.0 symbolic body descriptor prefix collisions bypass validation CVE-2026-67414 (medium): RabbitMQ AMQP 1.0 parser amplification memory-exhaustion DoS via zero-width array aggregation GHSA-27gv-h5q6-cpwg (low, CVE pending): RabbitMQ policymaker RCE through federation-management nonmember RPC and distribution reflection GHSA-pj8f-mw2q-3xjj (low, CVE pending): Consistent-hash exchange empty array crashes DLX queue processes CVE-2026-67418 (low): MQTT 5.0 inapplicable PUBLISH property disconnects matching subscribers CVE-2026-67420 (low): OAuth credential refresh retains revoked runtime tags GHSA-4826-gphh-vw3x (low, CVE pending): MQTT 5.0 Receive Maximum zero disables delivery credit https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-cfqc-c682-93mm https://nvd.nist.gov/vuln/detail/CVE-2026-67421 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6gmw-wxch-cvvc https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6xpg-rfmh-grhq https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-3526-xvv4-q9mr https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6chv-gv3h-cvcj https://nvd.nist.gov/vuln/detail/CVE-2026-67416 https://nvd.nist.gov/vuln/detail/CVE-2026-67414 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-27gv-h5q6-cpwg https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj8f-mw2q-3xjj https://nvd.nist.gov/vuln/detail/CVE-2026-67418 https://nvd.nist.gov/vuln/detail/CVE-2026-67420 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-4826-gphh-vw3x |
Product Version Release Advisory
- Open Source RabbitMQ 4.2.10
Security Fixes
This release has the following security fixes, listed by component and area.
|
Component |
Vulnerabilities Resolved |
|
Web STOMP Plugin |
GHSA-cfqc-c682-93mm (high) |
|
Management Plugin (OAuth2 UI) |
CVE-2026-67421 (medium) |
|
Shovel Management Plugin |
GHSA-6gmw-wxch-cvvc (medium) |
|
STOMP Plugin |
GHSA-6xpg-rfmh-grhq (medium) |
|
Core (Erlang distribution) |
GHSA-3526-xvv4-q9mr (medium) |
|
Core (direct reply-to) |
GHSA-6chv-gv3h-cvcj (medium) |
|
Core (AMQP 1.0) |
CVE-2026-67416 (medium) |
|
Core (AMQP 1.0) |
CVE-2026-67414 (medium) |
|
Federation Management Plugin |
GHSA-27gv-h5q6-cpwg (low) |
|
Consistent Hash Exchange Plugin |
GHSA-pj8f-mw2q-3xjj (low) |
|
MQTT Plugin |
CVE-2026-67418 (low) |
|
OAuth2 Plugin |
CVE-2026-67420 (low) |
|
MQTT Plugin |
GHSA-4826-gphh-vw3x (low) |
Product Versions Affected
- Open Source RabbitMQ >= 4.2.0, < 4.2.10
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.2.0, < 4.2.10
- VMware Tanzu RabbitMQ on Kubernetes >= 4.2.0, < 4.2.10