SB20260928419 - openEuler 20.03 LTS SP4 update for rabbitmq-server
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2021-22116)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing AMPQ messages in AMQP 1.0 client connection endpoint.. A remote attacker can send specially crafted input to the application and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that AMQP 1.0 plugin is enabled.
2) Cross-site scripting (CVE-ID: CVE-2026-57214)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.
The vulnerability exists due to cross-site scripting in the RabbitMQ management UI queue and exchange listing pages when rendering the x-internal-purpose queue or exchange argument into an HTML title attribute. A remote user can declare a queue or exchange with a crafted x-internal-purpose value to execute arbitrary JavaScript in the browser of another user.
The payload is stored in queue or exchange metadata and is triggered when a user views the Queues or Exchanges page.
3) Improper access control (CVE-ID: CVE-2026-57215)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject messages into another tenant's reply channel and cause silent routing loss conditions.
The vulnerability exists due to improper access control in direct-reply-to binding handling when binding and unbinding volatile amq.rabbitmq.reply-to.* destinations. A remote user can create and retain a crafted binding to inject messages into another tenant's reply channel and cause silent routing loss conditions.
Exploitation requires normal bind and publish permissions in a shared virtual host.
4) Improper access control (CVE-ID: CVE-2026-57216)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass loopback-only authentication restrictions and obtain a live AMQP session as a loopback-restricted user.
The vulnerability exists due to improper access control in the loopback-user check in RabbitMQ listener authentication when processing connections accepted through a trusted PROXY-protocol frontend on a loopback-bound backend listener. A remote attacker can send a specially crafted PROXY-protocol connection with valid loopback-restricted credentials to bypass loopback-only authentication restrictions and obtain a live AMQP session as a loopback-restricted user.
Exploitation requires access to a trusted PROXY-protocol path and valid credentials for a user restricted to loopback connections.
5) Missing Authorization (CVE-ID: CVE-2026-57221)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in passive queue.declare and passive exchange.declare operations when handling authenticated AMQP requests within a virtual host. A remote user can issue passive declare operations to disclose sensitive information.
Even users with empty configure, write, and read permission regexes can enumerate queue and exchange names, and passive queue declarations also expose message counts and consumer counts.
6) Inefficient regular expression complexity (CVE-ID: CVE-2026-67413)
CWE-ID: CWE-1333 - Inefficient Regular Expression Complexity
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the rabbitmq_jms_topic_exchange plugin when processing client-supplied JMS selectors during message routing. A remote user can bind an x-jms-topic exchange with an ambiguous LIKE pattern and repeatedly publish matching-shaped header values to cause a denial of service.
The issue affects the optional first-party JMS Topic Exchange plugin and delays publisher confirms while consuming broker CPU on the routing path.
Remediation
Install update from vendor's website.