Known vulnerabilities in RabbitMQ Server 4.2.0-rc.1

Vendor: Broadcom
Version: 4.2.0-rc.1
Software CPE: cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 66
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting RabbitMQ Server version 4.2.0-rc.1 RabbitMQ Server 4.2.0-rc.1 is affected by 66 vulnerabilities: 2 high, 16 medium, 48 low Critical High Medium Low

Vulnerabilities (66)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU143940 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2026-67421
CWE-80 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143938 - Improper input validation
CVE-2026-67418
CWE-20 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143937 - Improper Access Control
CVE-2026-67420
CWE-284 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143932 - Improper Access Control
CWE-284 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143931 - Improper Access Control
CWE-284 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143930 - Allocation of Resources Without Limits or Throttling
CWE-770 Medium
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU143929 - Insufficiently Protected Credentials
CWE-522 Low
No
No
3.13.19, 4.0.24, 4.1.15, 4.2.10, 4.3.5 18.08.2026 SB2026081823
#VU139301 - Resource exhaustion
CWE-400 Low
No
No
4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139297 - Resource exhaustion
CWE-400 Low
No
No
4.0.22, 4.1.14, 4.2.7, 4.3.1 24.07.2026 SB2026072454
#VU139296 - Unchecked Return Value
CWE-252 Medium
No
No
3.13.18, 4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139295 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139294 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139293 - Improper Encoding or Escaping of Output
CWE-116 Low
No
No
4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139292 - Incorrect Authorization
CWE-863 Low
No
No
3.13.18, 4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139291 - Missing Authorization
CWE-862 Low
No
No
3.13.18, 4.0.24, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139290 - Inefficient Regular Expression Complexity
CWE-1333 Low
No
No
4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139289 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CWE-90 Low
No
No
3.13.18, 4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139288 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Medium
No
No
3.13.18, 4.0.23, 4.1.14, 4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139287 - Improper Access Control
CWE-284 Low
No
No
4.2.9, 4.3.3 24.07.2026 SB2026072454
#VU139286 - Insufficient Session Expiration
CWE-613 Medium
No
No
4.2.9, 4.3.3 24.07.2026 SB2026072454


Showing elements 1 - 20 out of 66