Skip to main content
EPSS 0.2%top 87%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
High
Published: 09/15/2026 (09/15/2026, 13:31:52 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A Cross-Site Scripting (XSS) vulnerability exists in RabbitMQ within Red Hat Hardened Images due to unsanitized virtual host names in the management UI. Exploitation requires high privileges and user interaction, specifically the ability to force a virtual host restart. The impact on confidentiality and integrity is low. Red Hat has released an update including rabbitmq-server4.3-4.3.6-1.hum1 packages to address this and related issues. Mitigation includes restricting access to the RabbitMQ management UI to trusted administrators and ensuring it is not exposed to untrusted networks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 06:10:04 UTC

Technical Analysis

CVE-2026-44839 is a vulnerability in RabbitMQ where unsanitized virtual host names allow for Cross-Site Scripting (XSS) in the management UI pages listing virtual hosts. Successful exploitation requires an attacker with high privileges to force a virtual host restart and user interaction. The vulnerability has a low impact on confidentiality and integrity. Red Hat has issued an update for Red Hat Hardened Images RPMs, including rabbitmq-server4.3-4.3.6-1.hum1, to fix this issue. The advisory emphasizes restricting management UI access to trusted administrators as a mitigation.

Potential Impact

An attacker with high privileges could exploit this XSS vulnerability to execute malicious scripts in the RabbitMQ management UI, potentially leading to limited confidentiality and integrity impacts. The attack surface is limited due to the requirement for high privileges and user interaction. There is no impact on availability. The vulnerability could allow disclosure of sensitive information or unauthorized actions within the management UI context.

Mitigation Recommendations

A fix is available in the updated rabbitmq-server4.3-4.3.6-1.hum1 packages provided by Red Hat. Users should apply this update to remediate the vulnerability. Additionally, restrict access to the RabbitMQ management UI to trusted administrators only and ensure it is not exposed to untrusted networks to reduce the risk of exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:67552
Cve Count
7
Additional Cves
["CVE-2026-66067","CVE-2026-66072","CVE-2026-66074","CVE-2026-67219","CVE-2026-67232","CVE-2026-67235"]
State
PUBLISHED

Threat ID: 6ab4be13f7a7c54106eee31d

Added to database: 09/24/2026, 06:07:15 UTC

Last enriched: 09/24/2026, 06:10:04 UTC

Last updated: 09/25/2026, 01:47:42 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses