CVE-2026-57214
rabbitmq rabbitmq-server, rabbitmq server 취약점
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.
- 대응 우선순위
- 점검
- CVSS
- 7.1
- EPSS
- 0.22% 백분위 12.5% · 2026.07.20 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.11