CVE-2026-44839: RabbitMQ: Unsanitized vhost names allow for XSS in management UI
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
Other sources
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.7-7 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 4.1.2 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 4.0.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44839?
CVE-2026-44839 has a medium severity score of 5.6 according to the CVSS.
How do I fix CVE-2026-44839?
To address CVE-2026-44839, upgrade RabbitMQ to versions 4.1.2 or 4.0.13 or later.
What type of vulnerability is CVE-2026-44839?
CVE-2026-44839 is a Cross-Site Scripting (XSS) vulnerability affecting the RabbitMQ management UI.
Which versions of RabbitMQ are affected by CVE-2026-44839?
RabbitMQ versions from 3.7.0 up to but not including 4.1.2 and 4.0.13 are affected by CVE-2026-44839.
Is there a workaround for CVE-2026-44839?
There are no specific workarounds mentioned for CVE-2026-44839, but upgrading to a patched version is recommended.