// OSSeva Blog
SecurityRabbitMQ Vulnerabilities by Version: CVEs for RabbitMQ 3.x, 4.0, 4.1, 4.2 and 4.3
The short answer
Only RabbitMQ 4.3 still has community support, until 30 November 2026, and its latest release is 4.3.6. Community support for 4.2 ended on 31 July 2026, and the last 4.2 release on GitHub is 4.2.9 from 20 July 2026. 4.1 ended on 31 January 2026 with 4.1.8, 4.0 on 30 April 2025 with 4.0.9, and 3.13 on 30 September 2024 with 3.13.7. Later patch releases on those lines go only to Broadcom's commercial customers, so advisories often name a fixed version you cannot download. In 2026 the rabbitmq-server repository has published 83 security advisories, 70 of them with CVE IDs. 44 list 3.13 as affected and 54 list 4.0, and none of those has a public fix on that line.
RabbitMQ release lines and their 2026 advisories
Support dates are from rabbitmq.com's release information page; commercial dates are the ones it marks as indicative. The advisory counts are the GitHub security advisories published in 2026 whose affected ranges include the line, and a fix counts as public when the fixed release is on the rabbitmq-server GitHub releases page.
| Line | End of community support | End of commercial support | Last public release | 2026 advisories naming it | With a public fix |
|---|---|---|---|---|---|
| 4.3 | 30 November 2026 | 30 April 2028 | 4.3.6 | 46 | 46 |
| 4.2 | 31 July 2026 | 30 June 2030 | 4.2.9 | 79 | 63; 16 are fixed only in 4.2.10 or 4.2.11 |
| 4.1 | 31 January 2026 | 30 April 2027 | 4.1.8 | 58 | 1 |
| 4.0 | 30 April 2025 | 30 September 2026 | 4.0.9 | 54 | None |
| 3.13 | 30 September 2024 | 31 December 2029 | 3.13.7 | 44 | None |
| 3.12 | 29 February 2024 | 30 June 2025 | 3.12.14 | Not listed | No upstream fix on this line |
| 3.11 | 30 June 2023 | 30 June 2024 | 3.11.28 | Not listed | No upstream fix on this line |
| 3.10 | 30 September 2022 | 31 December 2023 | 3.10.25 | Not listed | No upstream fix on this line |
| 3.8 and 3.9 | Before 3.10; no longer on the page | Ended | 3.8.35; 3.9.29 | Not listed | No upstream fix on these lines |
The release information page also lists a 4.2.10 release dated 17 August 2026, but its GitHub tag is not public, which is why the 16 advisories fixed in 4.2.10 or 4.2.11 count as having no public fix. The 2026 advisories give ranges that start at 3.13.0, so "not listed" for 3.12 and older means nobody assessed those lines. It does not mean they are safe. The RabbitMQ end-of-life chart has the dates for every line.
Notable RabbitMQ CVEs by release line
The September 2026 batch, including the two critical CVEs CVE-2026-67404 (9.2) and CVE-2026-67231 (9.1), is covered line by line in RabbitMQ September 2026 CVEs. The table below covers the CVEs from earlier advisories. CVSS is NVD's own score where NVD has scored the record, otherwise GitHub's score as the CNA.
| CVE | Issue | CVSS | Fixed in a public release | Fixed only in a commercial release |
|---|---|---|---|---|
| CVE-2026-57215 | Bindings to direct reply-to destinations survive unbind, so another client can inject into a reply channel | 8.8 (NVD) | 4.2.6 | 3.13.15, 4.0.20, 4.1.11 |
| CVE-2026-44838 | MQTT topic authorization inserts the client ID into a regex unescaped, so a user can widen their own access | 8.1 (NVD) | 4.2.4, 4.3.0 | None; only 4.2 is affected |
| CVE-2026-57212 | The management HTTP API accepts request bodies larger than the configured limit | 7.7 (NVD) | 4.2.5 | 3.13.14, 4.0.19, 4.1.10 |
| CVE-2026-57219 | The obsolete GET /api/auth endpoint discloses the OAuth 2 client secret without authentication | 7.5 (NVD) | 4.2.6 | 3.13.15, 4.0.20, 4.1.11 |
| CVE-2026-57220 | The stream listener ignores its frame size limit before authentication | 7.5 (GitHub) | 4.2.6 | None; only 4.2 is listed |
| CVE-2022-31008 | Shovel and Federation obfuscate URIs with a predictable key, so credentials can be recovered from logs | 7.5 (NVD); 5.5 (GitHub) | 3.8.32, 3.9.18, 3.10.2 | None |
| CVE-2021-22116 | Malformed AMQP 1.0 messages cause denial of service | 7.5 (NVD) | 3.8.16 | None |
| CVE-2026-57217 | Topic authorization allows writes and binds when a Khepri permission lookup fails | 6.5 (NVD) | 4.2.6 | 3.13.15, 4.0.21, 4.1.11 |
| CVE-2024-51988 | HTTP API queue deletion does not check the configure permission | 6.5 (GitHub) | 3.12.11; 3.12.8 to 3.12.10 affected | None |
| CVE-2025-30219 | Management UI shows an unescaped virtual host name in an error message | 6.1 (GitHub) | 4.0.3 | 3.13.8 |
| CVE-2025-50200 | HTTP API errors log the Basic Auth header, which is base64 of the username and password | 5.5 (NVD) | 4.0.8 | 3.13.8 |
| CVE-2023-46118 | The HTTP API has no request body limit, so a large publish can exhaust node memory | 4.9 (NVD) | 3.11.24, 3.12.7 | None |
| CVE-2026-44839 | Virtual host names are not escaped on the vhost restart forms | 4.8 (NVD) | 4.1.2 | 4.0.13; NVD lists 3.7.0 onward as affected |
None of the RabbitMQ CVEs is in CISA's Known Exploited Vulnerabilities catalogue. Most need the management plugin, an OAuth 2 configuration or a specific protocol plugin, so rabbitmq-plugins list -e on each node tells you which rows apply.
What each line gets
RabbitMQ 4.3
Every 2026 advisory that names 4.3 has a public fix, the latest of them in 4.3.6. Community support ends on 30 November 2026, and GitHub shows no 4.4 release yet, so after that date 4.3 will be in the position 4.2 is in now. See RabbitMQ 4.3 end of life.
RabbitMQ 4.2
4.2.9 closes 63 of the 79 advisories that name 4.2, including every CVE in the table above that applies to 4.2. The other 16 came out after community support ended and are fixed only in 4.2.10 or 4.2.11. Moving to 4.3 is a minor upgrade. See RabbitMQ 4.2 end of life.
RabbitMQ 4.1 and 4.0
On 4.1 only CVE-2026-44839 has a public fix, in 4.1.2. Everything else from 2026, including CVE-2026-57215, CVE-2026-57219 and the two critical September CVEs, is fixed in 4.1.10, 4.1.11 or later, which are commercial. 4.0 has no public fix for any 2026 advisory, and Broadcom's commercial support for it ended on 30 September 2026. Releases 4.0.1 to 4.0.3 also run only on Erlang/OTP 26, which reached end of life in May 2026. See RabbitMQ 4.1 end of life and RabbitMQ 4.0 end of life.
RabbitMQ 3.13
3.13.7 has no public fix for any of the 44 advisories from 2026, nor for CVE-2025-50200 or CVE-2025-30219, which were fixed in the commercial 3.13.8. Public 3.13 releases run only on Erlang/OTP 26, so the runtime has stopped getting fixes too, including the TLS client flaw CVE-2026-89422. 3.13 is also the required stepping stone to 4.x, and 4.x removes classic mirrored queues. See RabbitMQ 3.13 end of life and Erlang/OTP vulnerabilities by version.
RabbitMQ 3.12 and older
3.12 reached the end of community support on 29 February 2024, and its last release, 3.12.14, came out in May 2024. It has the fixes for CVE-2023-46118 from 3.12.7 and CVE-2024-51988 from 3.12.11. 3.11 stopped at 3.11.28 and 3.10 at 3.10.25. The 2026 advisories do not assess these lines, but CVE-2025-50200 and CVE-2026-44839 have NVD ranges that reach back into 3.x. These lines also run on Erlang/OTP 26 or older, and no OTP release that old gets fixes any more. See RabbitMQ 3.12 end of life, RabbitMQ 3.11 end of life and RabbitMQ 3.8 end of life.
What to do on each line
- 4.3. Stay on 4.3.6 or later, and plan for the end of community support on 30 November 2026.
- 4.2. Move to 4.3.6.
- 4.1 and 4.0. Move to 4.3, or take patched builds. Check the Erlang/OTP release under any 4.0.1 to 4.0.3 node.
- 3.13. Plan the move to 4.x, which starts with replacing classic mirrored queues with quorum queues, or take patched broker and Erlang/OTP builds. See the mirrored to quorum queues migration guide.
- 3.12 and older. Upgrade to 3.13 first, since 4.x requires it, or take patched builds. Until then, keep the management plugin off untrusted networks, disable plugins you do not use, and set an explicit CA bundle for any OAuth 2 configuration.
Which Erlang/OTP release a broker can run is set by the broker version. RabbitMQ and Erlang version compatibility lists the pairs, and RabbitMQ CVE analysis for EOL versions covers the plugin attack surface in more depth.
Where OSSeva fits
OSSeva backports RabbitMQ security fixes to the 3.9 to 3.13 lines and to 4.0, 4.1 and 4.2, and to 3.8 where a backport is feasible, with a documented mitigation where it is not. The builds come from community source, not a fork, and ship with a tested Erlang/OTP release that gets its own CVE fixes, so a 3.13 cluster gets a patched broker and a patched runtime together. They are available now on the Patch, Assure and Operate tiers. Assure adds a configuration and architecture audit and version upgrade planning, and Operate adds 24/7 monitoring with a 15-minute P1 response and a named senior engineer. See RabbitMQ extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.