SB20260928421 - openEuler 24.03 LTS SP1 update for rabbitmq-server
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2023-46118)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the HTTP API. A remote administrator can trigger resource exhaustion and perform a denial of service (DoS) attack.
2) Cross-site scripting (CVE-ID: CVE-2025-30219)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in an error message in Management UI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
3) Stored cross-site scripting (CVE-ID: CVE-2026-44839)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper neutralization of script-related html tags in a web page in the management UI pages that list virtual hosts when rendering unsanitized virtual host names in restart forms. A remote privileged user can create a crafted virtual host name and force the virtual host to restart to disclose sensitive information.
User interaction is required because a victim must visit the page of the malicious virtual host.
4) Input validation error (CVE-ID: CVE-2026-57212)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the management HTTP API when handling oversized request bodies. A remote attacker can send a specially crafted request body to cause a denial of service.
5) Cross-site scripting (CVE-ID: CVE-2026-57213)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script code in a user's browser.
The vulnerability exists due to cross-site scripting in the federation management plugin when rendering an unsanitized consumer_tag. A remote user can inject a crafted consumer_tag value to execute arbitrary script code in a user's browser.
6) Cross-site scripting (CVE-ID: CVE-2026-57214)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.
The vulnerability exists due to cross-site scripting in the RabbitMQ management UI queue and exchange listing pages when rendering the x-internal-purpose queue or exchange argument into an HTML title attribute. A remote user can declare a queue or exchange with a crafted x-internal-purpose value to execute arbitrary JavaScript in the browser of another user.
The payload is stored in queue or exchange metadata and is triggered when a user views the Queues or Exchanges page.
7) Improper access control (CVE-ID: CVE-2026-57215)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject messages into another tenant's reply channel and cause silent routing loss conditions.
The vulnerability exists due to improper access control in direct-reply-to binding handling when binding and unbinding volatile amq.rabbitmq.reply-to.* destinations. A remote user can create and retain a crafted binding to inject messages into another tenant's reply channel and cause silent routing loss conditions.
Exploitation requires normal bind and publish permissions in a shared virtual host.
8) Improper access control (CVE-ID: CVE-2026-57216)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass loopback-only authentication restrictions and obtain a live AMQP session as a loopback-restricted user.
The vulnerability exists due to improper access control in the loopback-user check in RabbitMQ listener authentication when processing connections accepted through a trusted PROXY-protocol frontend on a loopback-bound backend listener. A remote attacker can send a specially crafted PROXY-protocol connection with valid loopback-restricted credentials to bypass loopback-only authentication restrictions and obtain a live AMQP session as a loopback-restricted user.
Exploitation requires access to a trusted PROXY-protocol path and valid credentials for a user restricted to loopback connections.
9) Missing Authorization (CVE-ID: CVE-2026-57221)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in passive queue.declare and passive exchange.declare operations when handling authenticated AMQP requests within a virtual host. A remote user can issue passive declare operations to disclose sensitive information.
Even users with empty configure, write, and read permission regexes can enumerate queue and exchange names, and passive queue declarations also expose message counts and consumer counts.
10) Unchecked Return Value (CVE-ID: CVE-2026-67409)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unchecked return value in the JWKS key fetching mechanism in uaa_jwt.erl when processing JWKS endpoint responses during signing key refresh. A remote attacker can send a crafted JWT with an unknown kid value to cause a denial of service.
Exploitation requires RabbitMQ to be configured with OAuth2 authentication using JWKS-based key discovery, and the JWKS endpoint must return an error response with a valid JSON body that lacks a keys field.
11) Inefficient regular expression complexity (CVE-ID: CVE-2026-67413)
CWE-ID: CWE-1333 - Inefficient Regular Expression Complexity
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the rabbitmq_jms_topic_exchange plugin when processing client-supplied JMS selectors during message routing. A remote user can bind an x-jms-topic exchange with an ambiguous LIKE pattern and repeatedly publish matching-shaped header values to cause a denial of service.
The issue affects the optional first-party JMS Topic Exchange plugin and delays publisher confirms while consuming broker CPU on the routing path.
Remediation
Install update from vendor's website.