{"id":"SUSE-SU-2026:23869-1","summary":"Security update for rabbitmq-server","details":"This update for rabbitmq-server fixes the following issues:\n\n- CVE-2026-44839: XSS in management UI due to unsanitized vhost names (bsc#1266465).\n- CVE-2026-57212: The rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request\n  paths (bsc#1271318).\n- CVE-2026-57213: stored XSS in RabbitMQ federation management plugin via unsanitized consumer_tag rendering\n  (bsc#1271336).\n- CVE-2026-57214: stored XSS in RabbitMQ management UI (bsc#1271337).\n- CVE-2026-57215: direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent\n  phantom (bsc#1271338).\n- CVE-2026-57216: stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address\n  loopback checks (bsc#1271339).\n- CVE-2026-57217: topic authorization can lead to cross-tenant routing-key bypass (bsc#1271340).\n- CVE-2026-57218: consumer persistence can lead to post-revocation message disclosure in OAuth2 (bsc#1271343).\n- CVE-2026-57219: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less\n  common OAuth 2 configurations (bsc#1271344).\n- CVE-2026-57220: stream listener does not enforce configured frame-size limit during authentication, permitting\n  unauth'd mem-exhaust DoS (bsc#1271345).\n- CVE-2026-57221: passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to\n  unprivileged users (bsc#1271346).\n","modified":"2026-09-27T18:23:57.717529957Z","published":"2026-09-22T02:23:51Z","related":["CVE-2026-44839","CVE-2026-57212","CVE-2026-57213","CVE-2026-57214","CVE-2026-57215","CVE-2026-57216","CVE-2026-57217","CVE-2026-57218","CVE-2026-57219","CVE-2026-57220","CVE-2026-57221"],"upstream":["CVE-2026-44839","CVE-2026-57212","CVE-2026-57213","CVE-2026-57214","CVE-2026-57215","CVE-2026-57216","CVE-2026-57217","CVE-2026-57218","CVE-2026-57219","CVE-2026-57220","CVE-2026-57221"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623869-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266465"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271336"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271338"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271339"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271346"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279938"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44839"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57213"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57218"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57221"}],"affected":[{"package":{"name":"rabbitmq-server","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/rabbitmq-server&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.5-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"rabbitmq-server-plugins":"4.1.5-160000.2.1","rabbitmq-server-zsh-completion":"4.1.5-160000.2.1","erlang-rabbitmq-client":"4.1.5-160000.2.1","rabbitmq-server":"4.1.5-160000.2.1","rabbitmq-server-bash-completion":"4.1.5-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23869-1.json"}},{"package":{"name":"rabbitmq-server","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/rabbitmq-server&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.5-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"rabbitmq-server":"4.1.5-160000.2.1","rabbitmq-server-bash-completion":"4.1.5-160000.2.1","rabbitmq-server-plugins":"4.1.5-160000.2.1","rabbitmq-server-zsh-completion":"4.1.5-160000.2.1","erlang-rabbitmq-client":"4.1.5-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23869-1.json"}}],"schema_version":"1.9.0"}