Product Release Advisory - Open Source RabbitMQ 4.3.5
|
Advisory ID: |
TNZ-2026-0385 |
|
Severity: |
[High] |
|
Issue Date: |
09-04-2026 |
|
Updated on: |
|
|
Synopsis |
Open Source RabbitMQ 4.3.5 resolves 13 security vulnerabilities:
https://nvd.nist.gov/vuln/detail/CVE-2026-67419 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-cfqc-c682-93mm https://nvd.nist.gov/vuln/detail/CVE-2026-67421 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6gmw-wxch-cvvc https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6xpg-rfmh-grhq https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-3526-xvv4-q9mr https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6chv-gv3h-cvcj https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6588-rqcr-59pw https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-27gv-h5q6-cpwg https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj8f-mw2q-3xjj https://nvd.nist.gov/vuln/detail/CVE-2026-67418 https://nvd.nist.gov/vuln/detail/CVE-2026-67420 https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-4826-gphh-vw3x |
Product Version Release Advisory
- Open Source RabbitMQ 4.3.5
Security Fixes
This release has the following security fixes, listed by component and area.
|
Component |
Vulnerabilities Resolved |
|
Core (topic exchange routing) |
CVE-2026-67419 (high) |
|
Web STOMP Plugin |
GHSA-cfqc-c682-93mm (high) |
|
Management Plugin (OAuth2 UI) |
CVE-2026-67421 (medium) |
|
Shovel Management Plugin |
GHSA-6gmw-wxch-cvvc (medium) |
|
STOMP Plugin |
GHSA-6xpg-rfmh-grhq (medium) |
|
Core (Erlang distribution) |
GHSA-3526-xvv4-q9mr (medium) |
|
Core (direct reply-to) |
GHSA-6chv-gv3h-cvcj (medium) |
|
Core (AMQP 1.0) |
GHSA-6588-rqcr-59pw (medium) |
|
Federation Management Plugin |
GHSA-27gv-h5q6-cpwg (low) |
|
Consistent Hash Exchange Plugin |
GHSA-pj8f-mw2q-3xjj (low) |
|
MQTT Plugin |
CVE-2026-67418 (low) |
|
OAuth2 Plugin |
CVE-2026-67420 (low) |
|
MQTT Plugin |
GHSA-4826-gphh-vw3x (low) |
Product Versions Affected
- Open Source RabbitMQ >= 4.3.0, < 4.3.5
Other Products Versions Affected
- VMware Tanzu RabbitMQ >= 4.3.0, < 4.3.25
- VMware Tanzu RabbitMQ on Kubernetes >= 4.3.0, < 4.3.5