SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57213

MEDIUM · CVSS 4.8 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The rabbitmq_federation_management plugin in affected versions of RabbitMQ is vulnerable due to improper HTML escaping of the consumer_tag field on the Federation Status page, which could allow an attacker to execute JavaScript in the browser of users accessing that page. This vulnerability poses a medium risk as it could lead to cross-site scripting (XSS) attacks, potentially compromising user sessions or sensitive information. Organizations using RabbitMQ, especially those with the ability to configure federations or policies, should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57213
Severity
MEDIUM
CVSS
4.8
EPSS
0.25%
Java

Original NVD Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

Related CVEs

Other vulnerabilities affecting the same vendor(s)