CVE-2026-44839
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
| CWE | CWE-80 |
| Vendor | rabbitmq |
| Product | rabbitmq-server |
| Published | May 27, 2026 |
| Last Updated | May 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for rabbitmq rabbitmq-server
Be the first to know when new unknown vulnerabilities affecting rabbitmq rabbitmq-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
rabbitmq / rabbitmq-server
>= 3.7.0, < 4.0.13 >= 4.1.0-alpha, < 4.1.2