{"id":"CVE-2026-57214","title":"RabbitMQ is a messaging and streaming broker","summary":"RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, al…","severity":"none","cwe":["CWE-79"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57214","references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ec","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/15606","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/15608","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.5","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00387,"epssPercentile":0.32709,"ingestedAt":"2026-07-11T20:15:27.059Z","slug":"CVE-2026-57214","body":"## Overview\n\nRabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}