rabbit_common
Modules shared by rabbitmq-server and rabbitmq-erlang-client
Activity
- Latest release
- 1mo ago
- Total releases
- 280
- Cadence
- ~3 days
- Last 12 months
- 8
Details
- License
- MPL-2.0
- First release
- Aug 19, 2014
| Version | Released | |
|---|---|---|
4.3.4
minor
| ||
4.2.1
patch
| ||
4.1.6
patch
| ||
4.2.0-rc.1
pre
| ||
4.1.5-rc.2
pre
| ||
4.1.5-rc.1
pre
| ||
4.2.0
minor
| ||
4.1.5
minor
| ||
4.0.3
patch
| ||
4.0.3-rc.1
pre
| ||
4.0.2
patch
| ||
4.0.2-rc.2
pre
| ||
4.0.2-rc.1
pre
| ||
4.0.1
patch
| ||
4.0.0
major
| ||
4.0.0-rc.2
pre
| ||
4.0.0-rc.1
pre
| ||
3.13.7
patch
| ||
3.13.6
patch
| ||
3.13.5
patch
| ||
3.13.4
patch
| ||
3.13.3
patch
| ||
3.12.14
patch
| ||
3.13.2
patch
| ||
3.13.2-rc.1
pre
| ||
3.13.1
patch
| ||
3.13.0
minor
| ||
3.13.0-rc.6
pre
| ||
3.12.13
patch
| ||
3.13.0-rc.5
pre
| ||
3.12.12
patch
| ||
3.13.0-rc.4
pre
| ||
3.12.11
patch
| ||
3.11.28
patch
| ||
3.13.0-rc.3
pre
| ||
3.11.27
patch
| ||
3.12.10
patch
1 CVE
CVE-2024-51988
GHSA-pj33-75x5-32j4
BIT-rabbitmq-2024-51988
Nov 06, 2024
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
High
Network
Low
Low
None
SummaryQueue deletion via the HTTP API was not verifying the ImpactUsers who had all of the following:
could delete queues it had no (deletion) permissions for. WorkaroundsDisable management plugin and use, for example, Prometheus and Grafana for monitoring. OWASP ClassificationOWASP Top10 A01:2021 – Broken Access Control Affected versions
3.12.10
3.12.7
3.12.8
3.12.9
Fixed in
3.12.11
References Updated Dec 10, 2025 · Source: OSV.dev | ||
3.11.26
patch
| ||
3.12.9
patch
1 CVE
CVE-2024-51988
GHSA-pj33-75x5-32j4
BIT-rabbitmq-2024-51988
Nov 06, 2024
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
High
Network
Low
Low
None
SummaryQueue deletion via the HTTP API was not verifying the ImpactUsers who had all of the following:
could delete queues it had no (deletion) permissions for. WorkaroundsDisable management plugin and use, for example, Prometheus and Grafana for monitoring. OWASP ClassificationOWASP Top10 A01:2021 – Broken Access Control Affected versions
3.12.10
3.12.7
3.12.8
3.12.9
Fixed in
3.12.11
References Updated Dec 10, 2025 · Source: OSV.dev | ||
3.13.0-rc.2
pre
| ||
3.12.8
patch
1 CVE
CVE-2024-51988
GHSA-pj33-75x5-32j4
BIT-rabbitmq-2024-51988
Nov 06, 2024
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
High
Network
Low
Low
None
SummaryQueue deletion via the HTTP API was not verifying the ImpactUsers who had all of the following:
could delete queues it had no (deletion) permissions for. WorkaroundsDisable management plugin and use, for example, Prometheus and Grafana for monitoring. OWASP ClassificationOWASP Top10 A01:2021 – Broken Access Control Affected versions
3.12.10
3.12.7
3.12.8
3.12.9
Fixed in
3.12.11
References Updated Dec 10, 2025 · Source: OSV.dev | ||
3.11.25
patch
| ||
3.13.0-rc.1
pre
| ||
3.12.7
patch
1 CVE
CVE-2024-51988
GHSA-pj33-75x5-32j4
BIT-rabbitmq-2024-51988
Nov 06, 2024
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
High
Network
Low
Low
None
SummaryQueue deletion via the HTTP API was not verifying the ImpactUsers who had all of the following:
could delete queues it had no (deletion) permissions for. WorkaroundsDisable management plugin and use, for example, Prometheus and Grafana for monitoring. OWASP ClassificationOWASP Top10 A01:2021 – Broken Access Control Affected versions
3.12.10
3.12.7
3.12.8
3.12.9
Fixed in
3.12.11
References Updated Dec 10, 2025 · Source: OSV.dev | ||
3.11.24
patch
| ||
3.12.6
patch
1 CVE
CVE-2023-46118
GHSA-w6cq-9cf4-gqpg
BIT-rabbitmq-2023-46118
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
SummaryResponsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. DetailsAn authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ImpactDenial of Service Affected versions
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6
3.11.0
3.11.1
3.11.10
3.11.11
3.11.12
+ 19 more Show less
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.2
3.11.20
3.11.21
3.11.22
3.11.23
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
Fixed in
3.11.24
3.12.7
References Updated Jun 30, 2026 · Source: OSV.dev | ||
3.12.5
patch
1 CVE
CVE-2023-46118
GHSA-w6cq-9cf4-gqpg
BIT-rabbitmq-2023-46118
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
SummaryResponsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. DetailsAn authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ImpactDenial of Service Affected versions
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6
3.11.0
3.11.1
3.11.10
3.11.11
3.11.12
+ 19 more Show less
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.2
3.11.20
3.11.21
3.11.22
3.11.23
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
Fixed in
3.11.24
3.12.7
References Updated Jun 30, 2026 · Source: OSV.dev | ||
3.11.23
patch
1 CVE
CVE-2023-46118
GHSA-w6cq-9cf4-gqpg
BIT-rabbitmq-2023-46118
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
SummaryResponsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. DetailsAn authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ImpactDenial of Service Affected versions
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6
3.11.0
3.11.1
3.11.10
3.11.11
3.11.12
+ 19 more Show less
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.2
3.11.20
3.11.21
3.11.22
3.11.23
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
Fixed in
3.11.24
3.12.7
References Updated Jun 30, 2026 · Source: OSV.dev | ||
3.11.22
patch
1 CVE
CVE-2023-46118
GHSA-w6cq-9cf4-gqpg
BIT-rabbitmq-2023-46118
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
SummaryResponsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. DetailsAn authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ImpactDenial of Service Affected versions
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6
3.11.0
3.11.1
3.11.10
3.11.11
3.11.12
+ 19 more Show less
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.2
3.11.20
3.11.21
3.11.22
3.11.23
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
Fixed in
3.11.24
3.12.7
References Updated Jun 30, 2026 · Source: OSV.dev | ||
3.12.4
patch
1 CVE
CVE-2023-46118
GHSA-w6cq-9cf4-gqpg
BIT-rabbitmq-2023-46118
Jun 30, 2026
RabbitMQ vulnerable to Denial of Service by publishing large messages over the HTTP API
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
None
High
SummaryResponsibly disclosed by @NSEcho. HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages. DetailsAn authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. A PoC was provided to Team RabbitMQ privately. ImpactDenial of Service Affected versions
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.12.5
3.12.6
3.11.0
3.11.1
3.11.10
3.11.11
3.11.12
+ 19 more Show less
3.11.13
3.11.14
3.11.15
3.11.16
3.11.17
3.11.18
3.11.19
3.11.2
3.11.20
3.11.21
3.11.22
3.11.23
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
Fixed in
3.11.24
3.12.7
References Updated Jun 30, 2026 · Source: OSV.dev |