CVE-2016-9877: Broadcom Rabbitmq Server

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.

Affected products

  • Broadcom Rabbitmq Server: version 3.0.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.1.0 only; …
  • Pivotal Software Rabbitmq: version 3.5.4 only; version 3.5.5 only; version 3.5.7 only; version 3.6.0 only; version 3.6.1 only; version 3.6.2 only; …

Published 2016-12-29. Last modified 2026-06-17.