CVE-2026-57213: Broadcom Rabbitmq Server
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
Affected products
- Broadcom Rabbitmq Server: from 3.13.0, before 4.2.5 (fixed in 4.2.5)
Published 2026-07-10. Last modified 2026-07-14.