CVE-2026-57213: RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmqfederationmanagement plugin renders the consumertag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
Other sources
RabbitMQ: Stored XSS federation management plugin via unsanitized consumertag rendering
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.7-7 - Upgrade
Upgrade
RabbitMQ (rabbitmq_federation_management)to a version that resolves this vulnerability.Fixed in 3.13.14 - Upgrade
Upgrade
RabbitMQ (rabbitmq_federation_management)to a version that resolves this vulnerability.Fixed in 4.0.19 - Upgrade
Upgrade
RabbitMQ (rabbitmq_federation_management)to a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
RabbitMQ (rabbitmq_federation_management)to a version that resolves this vulnerability.Fixed in 4.2.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57213?
The severity of CVE-2026-57213 is rated as medium with a score of 5.7.
How do I fix CVE-2026-57213?
To fix CVE-2026-57213, upgrade RabbitMQ to versions 3.13.14, 4.0.19, 4.1.10, or 4.2.5 or later.
What type of vulnerability is CVE-2026-57213?
CVE-2026-57213 is a stored cross-site scripting (XSS) vulnerability in the RabbitMQ federation management plugin.
Which RabbitMQ plugin is affected by CVE-2026-57213?
The affected plugin for CVE-2026-57213 is the rabbitmq_federation_management plugin.
When was CVE-2026-57213 published?
CVE-2026-57213 was published on July 10, 2026.