Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44839

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

A flaw was found in RabbitMQ, a messaging and streaming broker. Unsanitized virtual host names allow for XSS in the the management UI pages that list virtual hosts if the attacker manages to find a way to force a virtual host to restart. This vulnerability requires high privileges and user interaction, potentially leading to a low impact on confidentiality and integrity.

Отчет

This flaw has a Low impact on Red Hat products. An attacker with high privileges could exploit an unsanitized virtual host name in the RabbitMQ management UI, leading to a Cross-Site Scripting (XSS) vulnerability. Successful exploitation requires user interaction and the ability to force a virtual host restart, limiting the attack surface.

Меры по смягчению последствий

To mitigate this issue, restrict access to the RabbitMQ management UI to trusted administrators only. Ensure that administrative interfaces are not exposed to untrusted networks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverFix deferred
Red Hat OpenStack Platform 17.1rabbitmq-serverFix deferred
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2482215rabbitmq-server: RabbitMQ: Unsanitized vhost names allow for XSS in management UI

EPSS

Процентиль: 8%
0.0018
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
2 месяца назад

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

CVSS3: 4.8
nvd
2 месяца назад

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

msrc
2 месяца назад

RabbitMQ: Unsanitized vhost names allow for XSS in management UI

CVSS3: 4.8
debian
2 месяца назад

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1 ...

github
3 месяца назад

Unsanitized vhost names allow for XSS in management UI

EPSS

Процентиль: 8%
0.0018
Низкий

3.5 Low

CVSS3