Back to blog

// OSSeva Blog

Security

RabbitMQ Vulnerabilities by Version: CVEs for RabbitMQ 3.x, 4.0, 4.1, 4.2 and 4.3

Matt Reynolds9 min read

The short answer

Only RabbitMQ 4.3 still has community support, until 30 November 2026, and its latest release is 4.3.6. Community support for 4.2 ended on 31 July 2026, and the last 4.2 release on GitHub is 4.2.9 from 20 July 2026. 4.1 ended on 31 January 2026 with 4.1.8, 4.0 on 30 April 2025 with 4.0.9, and 3.13 on 30 September 2024 with 3.13.7. Later patch releases on those lines go only to Broadcom's commercial customers, so advisories often name a fixed version you cannot download. In 2026 the rabbitmq-server repository has published 83 security advisories, 70 of them with CVE IDs. 44 list 3.13 as affected and 54 list 4.0, and none of those has a public fix on that line.

RabbitMQ release lines and their 2026 advisories

Support dates are from rabbitmq.com's release information page; commercial dates are the ones it marks as indicative. The advisory counts are the GitHub security advisories published in 2026 whose affected ranges include the line, and a fix counts as public when the fixed release is on the rabbitmq-server GitHub releases page.

LineEnd of community supportEnd of commercial supportLast public release2026 advisories naming itWith a public fix
4.330 November 202630 April 20284.3.64646
4.231 July 202630 June 20304.2.97963; 16 are fixed only in 4.2.10 or 4.2.11
4.131 January 202630 April 20274.1.8581
4.030 April 202530 September 20264.0.954None
3.1330 September 202431 December 20293.13.744None
3.1229 February 202430 June 20253.12.14Not listedNo upstream fix on this line
3.1130 June 202330 June 20243.11.28Not listedNo upstream fix on this line
3.1030 September 202231 December 20233.10.25Not listedNo upstream fix on this line
3.8 and 3.9Before 3.10; no longer on the pageEnded3.8.35; 3.9.29Not listedNo upstream fix on these lines

The release information page also lists a 4.2.10 release dated 17 August 2026, but its GitHub tag is not public, which is why the 16 advisories fixed in 4.2.10 or 4.2.11 count as having no public fix. The 2026 advisories give ranges that start at 3.13.0, so "not listed" for 3.12 and older means nobody assessed those lines. It does not mean they are safe. The RabbitMQ end-of-life chart has the dates for every line.

Notable RabbitMQ CVEs by release line

The September 2026 batch, including the two critical CVEs CVE-2026-67404 (9.2) and CVE-2026-67231 (9.1), is covered line by line in RabbitMQ September 2026 CVEs. The table below covers the CVEs from earlier advisories. CVSS is NVD's own score where NVD has scored the record, otherwise GitHub's score as the CNA.

CVEIssueCVSSFixed in a public releaseFixed only in a commercial release
CVE-2026-57215Bindings to direct reply-to destinations survive unbind, so another client can inject into a reply channel8.8 (NVD)4.2.63.13.15, 4.0.20, 4.1.11
CVE-2026-44838MQTT topic authorization inserts the client ID into a regex unescaped, so a user can widen their own access8.1 (NVD)4.2.4, 4.3.0None; only 4.2 is affected
CVE-2026-57212The management HTTP API accepts request bodies larger than the configured limit7.7 (NVD)4.2.53.13.14, 4.0.19, 4.1.10
CVE-2026-57219The obsolete GET /api/auth endpoint discloses the OAuth 2 client secret without authentication7.5 (NVD)4.2.63.13.15, 4.0.20, 4.1.11
CVE-2026-57220The stream listener ignores its frame size limit before authentication7.5 (GitHub)4.2.6None; only 4.2 is listed
CVE-2022-31008Shovel and Federation obfuscate URIs with a predictable key, so credentials can be recovered from logs7.5 (NVD); 5.5 (GitHub)3.8.32, 3.9.18, 3.10.2None
CVE-2021-22116Malformed AMQP 1.0 messages cause denial of service7.5 (NVD)3.8.16None
CVE-2026-57217Topic authorization allows writes and binds when a Khepri permission lookup fails6.5 (NVD)4.2.63.13.15, 4.0.21, 4.1.11
CVE-2024-51988HTTP API queue deletion does not check the configure permission6.5 (GitHub)3.12.11; 3.12.8 to 3.12.10 affectedNone
CVE-2025-30219Management UI shows an unescaped virtual host name in an error message6.1 (GitHub)4.0.33.13.8
CVE-2025-50200HTTP API errors log the Basic Auth header, which is base64 of the username and password5.5 (NVD)4.0.83.13.8
CVE-2023-46118The HTTP API has no request body limit, so a large publish can exhaust node memory4.9 (NVD)3.11.24, 3.12.7None
CVE-2026-44839Virtual host names are not escaped on the vhost restart forms4.8 (NVD)4.1.24.0.13; NVD lists 3.7.0 onward as affected

None of the RabbitMQ CVEs is in CISA's Known Exploited Vulnerabilities catalogue. Most need the management plugin, an OAuth 2 configuration or a specific protocol plugin, so rabbitmq-plugins list -e on each node tells you which rows apply.

What each line gets

RabbitMQ 4.3

Every 2026 advisory that names 4.3 has a public fix, the latest of them in 4.3.6. Community support ends on 30 November 2026, and GitHub shows no 4.4 release yet, so after that date 4.3 will be in the position 4.2 is in now. See RabbitMQ 4.3 end of life.

RabbitMQ 4.2

4.2.9 closes 63 of the 79 advisories that name 4.2, including every CVE in the table above that applies to 4.2. The other 16 came out after community support ended and are fixed only in 4.2.10 or 4.2.11. Moving to 4.3 is a minor upgrade. See RabbitMQ 4.2 end of life.

RabbitMQ 4.1 and 4.0

On 4.1 only CVE-2026-44839 has a public fix, in 4.1.2. Everything else from 2026, including CVE-2026-57215, CVE-2026-57219 and the two critical September CVEs, is fixed in 4.1.10, 4.1.11 or later, which are commercial. 4.0 has no public fix for any 2026 advisory, and Broadcom's commercial support for it ended on 30 September 2026. Releases 4.0.1 to 4.0.3 also run only on Erlang/OTP 26, which reached end of life in May 2026. See RabbitMQ 4.1 end of life and RabbitMQ 4.0 end of life.

RabbitMQ 3.13

3.13.7 has no public fix for any of the 44 advisories from 2026, nor for CVE-2025-50200 or CVE-2025-30219, which were fixed in the commercial 3.13.8. Public 3.13 releases run only on Erlang/OTP 26, so the runtime has stopped getting fixes too, including the TLS client flaw CVE-2026-89422. 3.13 is also the required stepping stone to 4.x, and 4.x removes classic mirrored queues. See RabbitMQ 3.13 end of life and Erlang/OTP vulnerabilities by version.

RabbitMQ 3.12 and older

3.12 reached the end of community support on 29 February 2024, and its last release, 3.12.14, came out in May 2024. It has the fixes for CVE-2023-46118 from 3.12.7 and CVE-2024-51988 from 3.12.11. 3.11 stopped at 3.11.28 and 3.10 at 3.10.25. The 2026 advisories do not assess these lines, but CVE-2025-50200 and CVE-2026-44839 have NVD ranges that reach back into 3.x. These lines also run on Erlang/OTP 26 or older, and no OTP release that old gets fixes any more. See RabbitMQ 3.12 end of life, RabbitMQ 3.11 end of life and RabbitMQ 3.8 end of life.

What to do on each line

  • 4.3. Stay on 4.3.6 or later, and plan for the end of community support on 30 November 2026.
  • 4.2. Move to 4.3.6.
  • 4.1 and 4.0. Move to 4.3, or take patched builds. Check the Erlang/OTP release under any 4.0.1 to 4.0.3 node.
  • 3.13. Plan the move to 4.x, which starts with replacing classic mirrored queues with quorum queues, or take patched broker and Erlang/OTP builds. See the mirrored to quorum queues migration guide.
  • 3.12 and older. Upgrade to 3.13 first, since 4.x requires it, or take patched builds. Until then, keep the management plugin off untrusted networks, disable plugins you do not use, and set an explicit CA bundle for any OAuth 2 configuration.

Which Erlang/OTP release a broker can run is set by the broker version. RabbitMQ and Erlang version compatibility lists the pairs, and RabbitMQ CVE analysis for EOL versions covers the plugin attack surface in more depth.

Where OSSeva fits

OSSeva backports RabbitMQ security fixes to the 3.9 to 3.13 lines and to 4.0, 4.1 and 4.2, and to 3.8 where a backport is feasible, with a documented mitigation where it is not. The builds come from community source, not a fork, and ship with a tested Erlang/OTP release that gets its own CVE fixes, so a 3.13 cluster gets a patched broker and a patched runtime together. They are available now on the Patch, Assure and Operate tiers. Assure adds a configuration and architecture audit and version upgrade planning, and Operate adds 24/7 monitoring with a 15-minute P1 response and a named senior engineer. See RabbitMQ extended support.

Tags

RabbitMQCVERabbitMQ 3.13RabbitMQ 4.2End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.