Home

Description

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

PUBLISHED Reserved 2026-05-07 | Published 2026-05-27 | Updated 2026-05-27 | Assigner GitHub_M




MEDIUM: 5.6CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

>= 3.7.0, < 4.0.13
affected

>= 4.1.0-alpha, < 4.1.2
affected

References

github.com/...server/security/advisories/GHSA-fh5r-jpm3-fjwp

github.com/...ommit/7f54319279d1ece161ae0b4cdc6f0e58a4045eb5

cve.org (CVE-2026-44839)

nvd.nist.gov (CVE-2026-44839)

Download JSON