Bug 2499208 (CVE-2026-57213) - CVE-2026-57213 rabbitmq-server: RabbitMQ: Information Disclosure via Cross-Site Scripting in Federation Management
Summary: CVE-2026-57213 rabbitmq-server: RabbitMQ: Information Disclosure via Cross-Si...
Keywords:
Status: NEW
Alias: CVE-2026-57213
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2507942
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-10 21:01 UTC by OSIDB Bzimport
Modified: 2026-07-28 10:36 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-10 21:01:36 UTC
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.


Note You need to log in before you can comment on or make changes to this bug.