Messaging and Streaming Broker Vulnerability in RabbitMQ
CVE-2026-44839

5.6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
27 May 2026

What is CVE-2026-44839?

A flaw exists in RabbitMQ, a prominent messaging and streaming broker, affecting versions from 3.7.0 to before 4.1.2 and 4.0.13. This vulnerability could potentially expose sensitive data or create avenues for unauthorized access within the messaging system. Users are strongly encouraged to upgrade to version 4.1.2 or 4.0.13, where the vulnerability has been addressed. For details on the fix and further implications, refer to the official advisory links.

Affected Version(s)

rabbitmq-server >= 3.7.0, < 4.0.13 < 3.7.0, 4.0.13

rabbitmq-server >= 4.1.0-alpha, < 4.1.2 < 4.1.0-alpha, 4.1.2

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.