[Git][security-tracker-team/security-tracker][master] new rabbitmq-server issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 25 22:23:29 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
daa2c3e5 by Moritz Muehlenhoff at 2026-09-25T23:23:01+02:00
new rabbitmq-server issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -373,59 +373,107 @@ CVE-2026-6083 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API
CVE-2026-6082 (Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and ...)
TODO: check
CVE-2026-67421 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/commit/ff595eaaa6d4f580f72fa04801ffd35f48c46027 (v4.3.5)
CVE-2026-67420 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-86fm-44m9-rqjx
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/commit/5de287d213765ca592ff5848ad2f6b9b98ee6772 (v4.3.5)
CVE-2026-67419 (RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authe ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.3.x)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.3.x)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-h964-v5mf-22cq
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/commit/c5ed7c4e97e02be688730803604cc7a88dbe4864 (v4.3.5)
CVE-2026-67415 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-8mpg-qw9r-m5cr
CVE-2026-67413 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-chxf-3hfg-j8f7
CVE-2026-67412 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-42pc-678q-v8qj
CVE-2026-67411 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-4r6f-9cpw-f6g6
CVE-2026-67410 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-f9f2-q3jf-wfj3
CVE-2026-67409 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-qw3h-qqm9-jrw8
CVE-2026-67408 (RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.1.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.1.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-2hm4-4438-49q8
CVE-2026-67407 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q46v-hrvq-hp24
CVE-2026-67406 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q44f-9vc5-grh7
CVE-2026-67242 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rrj4-g94f-rqj9
CVE-2026-67241 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-rg2g-289m-xhhw
CVE-2026-67239 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-xm9p-57xv-vxwc
CVE-2026-67237 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-2rf7-f6r6-8rwh
CVE-2026-67236 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-88vh-gx85-p36m
CVE-2026-67234 (RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 a ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x and later)
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q286-p3m9-j69f
CVE-2026-67230 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7v63-j4gm-p4rh
CVE-2026-67227 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-q7x8-97rh-cr24
CVE-2026-67226 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-34c7-r8w9-5wv8
CVE-2026-67225 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c8c4-gvv4-8j3q
CVE-2026-67223 (RabbitMQ is a messaging and streaming broker. The advisory establishes ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-9x7r-g78c-5835
CVE-2026-67222 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-85jr-6rr2-j73r
CVE-2026-66078 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-j9m2-hw6x-rqr9
CVE-2026-66073 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6v53-r759-jrvx
CVE-2026-66071 (RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.1 ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-89p2-f5cv-x5cg
CVE-2026-65828 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
- zammad <itp> (bug #841355)
CVE-2026-63216 (Zammad is a web based open source helpdesk/customer support system. Pr ...)
@@ -449,7 +497,8 @@ CVE-2026-62062 (Cross-Site Request Forgery (CSRF) vulnerability in Elementor Web
CVE-2026-61855 (Zammad is a web based open source helpdesk/customer support system. In ...)
- zammad <itp> (bug #841355)
CVE-2026-61837 (RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, ...)
- TODO: check
+ - rabbitmq-server <unfixed>
+ NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-w9hf-476r-443x
CVE-2026-61525 (Zammad is a web based open source helpdesk/customer support system. In ...)
- zammad <itp> (bug #841355)
CVE-2026-60101
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daa2c3e5d2ab82ef88d283b4632c83ecc23115b7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/daa2c3e5d2ab82ef88d283b4632c83ecc23115b7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/2207788b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list