CVE-2026-44839

EUVD-2026-32549
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13,  This vulnerability is fixed in 4.1.2 and 4.0.13.
Basic XSS
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.61%
Affected Products (NVD)
VendorProductVersion
broadcomrabbitmq_server
3.7.0 ≤
𝑥
< 4.0.13
broadcomrabbitmq_server
4.1.0 ≤
𝑥
< 4.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rabbitmq-server
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
4.3.2-4
fixed
sid
4.3.2-4
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
broker
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rabbitmq-server
Azure Linux 3.0
0:3.13.7-8.azl3
fixed