[Git][security-tracker-team/security-tracker][master] Add more rabbitmq-java-client issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 19 08:01:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8dee2010 by Salvatore Bonaccorso at 2026-08-19T09:00:50+02:00
Add more rabbitmq-java-client issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -800,11 +800,26 @@ CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
 	TODO: check
 CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2000
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2002
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb (v5.33.0)
 CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2001
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339 (v5.33.0)
 CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-qx7j-jv8m-fppr
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1959
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/31735344d9f9dfc53740b67f06e560e8846b9322 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1960
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/abd6d60d4e2bfc1a327dc90ab246b2e8aca1f33b (v5.31.0)
 CVE-2026-63328 (Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata ...)
 	TODO: check
 CVE-2026-62684 (File Browser is a file managing interface for uploading, deleting, pre ...)
@@ -814,7 +829,12 @@ CVE-2026-62357 (Dragonfly is an in-memory data store built for modern applicatio
 CVE-2026-61696 (Forem is open source software for building communities. In versions be ...)
 	TODO: check
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
-	TODO: check
+	- rabbitmq-java-client <unfixed>
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591 (main)
+	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1995
+	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/b491075f42e89967610c40beded68d3680cfd472 (v5.33.0)
 CVE-2026-61574 (authentik is an open-source identity provider. Prior to 2026.2.6 and 2 ...)
 	TODO: check
 CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Expose ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8dee2010eb2b533e963011142ae3c9c0a442ec02

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8dee2010eb2b533e963011142ae3c9c0a442ec02
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/f825ec77/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list