Search CVE reports


Toggle filters

121 – 130 of 59603 results

Status is adjusted based on your filters.


CVE-2026-67242

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-expiry checks for float exp. validatetokenexpiry/1 (lines 208-214) and expirytimestamp/1 (138-144) both guard...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67241

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare skips alternate-exchange permission check. pUT /exchanges/:name (lines 192-240) checks only configure on the...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67239

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67237

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping,...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67236

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly,...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67234

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary/1 on the strict_auth_mechanism or preferred_auth_mechanism atom when clearing the corresponding cookie,...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67230

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSocket handler enforced neither max_frame_size nor login_timeout before authentication, allowing...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67227

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: toatom on global-parameter :name. resourceexists/2 (and the PUT/DELETE handlers)...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67226

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-67225

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's...

1 affected package

rabbitmq-server

Package 16.04 LTS
rabbitmq-server Needs evaluation
Show less packages