Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when an existing AMQP connection refreshes from an OAuth token that grants the impersonator tag to a valid same-username token that no longer grants that tag, RabbitMQ updates the OAuth backend implementation (token/scopes/expiry) but leaves the connection's runtime #user.tags unchanged. rabbitaccesscontrol:checkuserid/2 then still honors the stale impersonator tag, so the connection (including newly opened channels) can continue publishing messages with a foreign AMQP userid after that privilege should have been revoked. A fresh connection using the downgraded token correctly refuses the same publish, proving the defect is stale session state rather than the token Limited to connections that once held impersonator and successfully refresh to a downgraded same-username rabbitauthbackendoauth2 (or an equivalent refresh-capable backend that returns tags) is enabled for This issue is fixed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5. Join the discussion | CVE Database V5 | 09/25/2026, 16:42:49 UTC Added: 09/25/2026, 16:48:20 UTC |
0 CVE-2026-67419 is a high-severity vulnerability in rabbitmq-server prior to version 4.3.5. It involves inefficient algorithmic complexity in topic exchange routing, where an authenticated user with permissions to bind queues and publish messages can exploit consecutive '#' segments in binding keys. This causes excessive CPU and memory usage due to duplicate processing in topic matchers, potentially disrupting message routing for all tenants. The issue is fixed in version 4.3.5. Join the discussion | CVE Database V5 | 09/25/2026, 16:41:08 UTC Added: 09/25/2026, 16:48:20 UTC |
CVE-2026-67421 is a medium severity vulnerability in RabbitMQ server versions from 3.13.0 up to but not including 3.13.19, and several 4.x versions before specific patched releases. It involves missing authorization in the RabbitMQ Management interface when the OAuth management UI is enabled. An attacker with queue configure permission can cause an authorization error that reveals an attacker-controlled queue name in HTML, potentially allowing a management administrator to inadvertently leak their Authorization header to an attacker-controlled endpoint via a cross-origin request. This issue is fixed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5. Join the discussion | CVE Database V5 | 09/25/2026, 16:39:02 UTC Added: 09/25/2026, 16:48:20 UTC |
0 CVE-2026-67408 is a high-severity vulnerability in rabbitmq-server versions 4.1.0 through before 4.1.11, 4.2.0 through before 4.2.9, and 4.3.0 through before 4.3.3. It allows an authenticated low-privileged management user with access to a vhost but without configure, write, or read permissions to cause uncontrolled resource consumption. By sending a crafted HTTP PUT request to the stream management API with a large binding-keys field, the attacker can force large memory allocations before permission checks occur, potentially causing the RabbitMQ node to crash in memory-limited environments. The issue is fixed in versions 4.1.11, 4.2.9, and 4.3.3. Join the discussion | CVE Database V5 | 09/25/2026, 16:35:22 UTC Added: 09/25/2026, 16:48:21 UTC |
0 CVE-2026-67406 is a vulnerability in rabbitmq-server versions prior to 4.3.3, 4.2.9, 4.1.14, and 4.0.23 where the Shovel worker process does not properly format crash logs. This causes plaintext AMQP credentials to be exposed in error logs when the shovel worker crashes, which can happen during network issues. The issue affects multiple version branches and is fixed in the specified patched versions. Join the discussion | CVE Database V5 | 09/25/2026, 16:34:06 UTC Added: 09/25/2026, 16:48:21 UTC |
0 CVE-2026-67410 is a vulnerability in RabbitMQ server versions 4.2.0 through 4.2.8 and 4.3.0 through 4.3.2 where the OAuth2 client secret is exposed via an unauthenticated JavaScript endpoint. This occurs when OAuth2 authentication is enabled for the RabbitMQ Management UI and the configured flow uses a client secret. The secret is included in the JavaScript served by the unauthenticated endpoint /js/oidc-oauth/bootstrap.js, allowing any user who can access the management UI port to retrieve it. The issue is fixed in versions 4.2.9 and 4.3.3. Join the discussion | CVE Database V5 | 09/25/2026, 16:32:51 UTC Added: 09/25/2026, 16:48:21 UTC |
0 CVE-2026-67227 is a medium severity vulnerability in rabbitmq-server versions from 4.0.0 up to but not including 4.0.22, 4.1.14, 4.2.7, and 4.3.1. It involves uncontrolled resource consumption due to atom exhaustion triggered by a policymaker user making repeated requests to the /api/global-parameters/:name endpoint with unique :name values. This can crash the node by exhausting the atom table. The issue is fixed in versions 4.0.22, 4.1.14, 4.2.7, and 4.3.1. Join the discussion | CVE Database V5 | 09/25/2026, 16:31:45 UTC Added: 09/25/2026, 16:48:21 UTC |
CVE-2026-67407 is a medium severity vulnerability in rabbitmq-server affecting versions from 4.0.0 up to but not including 4.3.3, 4.2.9, 4.1.14, and 4.0.23. It is a missing authorization issue related to an incomplete fix for a previous vulnerability (CVE-2026-44838). The flaw involves improper escaping of the '-' character in MQTT topic permission templates, allowing a low-privileged authenticated MQTT user to broaden topic read and write permissions by manipulating the clientid in topic permission templates. This issue is fixed in versions 4.3.3, 4.2.9, 4.1.14, and 4.0.23. Join the discussion | CVE Database V5 | 09/25/2026, 16:30:35 UTC Added: 09/25/2026, 16:48:21 UTC |
0 CVE-2026-67226 is a medium severity vulnerability in rabbitmq-server affecting versions 4.0.0 up to but not including 4.0.22, 4.1.0 up to but not including 4.1.14, and 4.2.0 up to but not including 4.2.7. It involves uncontrolled resource consumption via an admin-only API endpoint that processes user tags. An administrator can crash the node by submitting a request with approximately one million unique tags. This issue has been fixed in versions 4.0.22, 4.1.14, and 4.2.7. Join the discussion | CVE Database V5 | 09/25/2026, 16:29:13 UTC Added: 09/25/2026, 16:48:20 UTC |
CVE-2026-67411 is an incorrect authorization vulnerability in rabbitmq-server affecting native MQTT and MQTT over WebSocket when used behind a trusted PROXY Protocol frontend. Versions from 3.13.0 up to but not including 3.13.18, 4.0.0 up to 4.0.23, 4.1.0 up to 4.1.14, 4.2.0 up to 4.2.9, and 4.3.0 up to 4.3.3 are affected. The flaw allows an attacker with valid credentials for a loopback-restricted account to bypass source-address restrictions due to loss of the proxy-derived client address before authentication checks. Password authentication is still required. The issue has been fixed in the specified later versions. Join the discussion | CVE Database V5 | 09/25/2026, 16:26:33 UTC Added: 09/25/2026, 16:48:21 UTC |
Showing 1 to 10 of 68 results