RabbitMQ
tool · Broadcom / VMware Tanzu
Current status
Supported version lines, end-of-life status, and latest releases for RabbitMQ — derived from official vendor sources, not third-party EOL aggregators.
RabbitMQ is an open-source message broker implementing AMQP and other messaging protocols for reliable asynchronous communication between services.
Security: 12 tracked advisories. Details below — lifecycle and vulnerability status are separate.
Official site →Version lines
11
Supported
11
EOL lines
0
Latest stable
4.3.5
2026-08-17
Releases tracked
205
At a glance
Latest release
4.3.5
Line 4.3
Recommended support line
4.3
standard support
Status
STANDARD SUPPORT
Newest supported: 4.3
EOL
Not published
Exact date not officially published
Recommended line: 4.3 (newest supported line with lowest lifecycle risk — not blindly “latest”).
Supported versions
11 currently supported release lines.
| Version line | Lifecycle | Latest release | Released | EOL | Risk |
|---|---|---|---|---|---|
| 4.3 | standard supportlow | 4.3.5 | 2026-08-17 | Not officially published | low |
| 4.2 | standard supportlow | 4.2.9 | 2026-07-20 | Not officially published | low |
| 4.1 | standard supportlow | 4.1.8 | 2026-01-22 | Not officially published | low |
| 4.0 | standard supportlow | 4.0.9 | 2025-04-14 | Not officially published | low |
| 3.13 | standard supportlow | 3.13.7 | 2024-08-26 | Not officially published | low |
| 3.12 | standard supportlow | 3.12.14 | 2024-05-05 | Not officially published | low |
| 3.11 | standard supportlow | 3.11.28 | 2023-12-22 | Not officially published | low |
| 3.10 | standard supportlow | 3.10.25 | 2023-07-18 | Not officially published | low |
| 3.9 | standard supportlow | 3.9.29 | 2023-03-09 | Not officially published | low |
| 3.8 | standard supportlow | 3.8.35 | 2022-07-09 | Not officially published | low |
| 3.7 | standard supportlow | 3.7.28 | 2020-08-17 | Not officially published | low |
Lifecycle overview
Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.
- 4.3standard supportstandard support
- 4.2standard supportstandard support
- 4.1standard supportstandard support
- 4.0standard supportstandard support
- 3.13standard supportstandard support
- 3.12standard supportstandard support
- 3.11standard supportstandard support
- 3.10standard supportstandard support
- 3.9standard supportstandard support
- 3.8standard supportstandard support
- 3.7standard supportstandard support
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2026-57217
RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
- Affected:
- >=3.13.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57221
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
- Affected:
- >=3.13.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57215
RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom
- Affected:
- >=3.13.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57219
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
- Affected:
- >=3.13.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57218
RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
- Affected:
- >=4.2.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57216
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
- Affected:
- >=3.13.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
- Affected:
- >=4.2.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57214
RabbitMQ: Stored XSS in RabbitMQ management UI
- Affected:
- >=4.2.0,<4.2.5
- Fixed in:
- 4.2.5
- Source:
- OSV source · Advisory
- CVE-2026-57211
RabbitMQ: UNC SSRF affecting the management UI on Windows
- Affected:
- >=4.1.0,<4.2.6
- Fixed in:
- 4.2.6
- Source:
- OSV source · Advisory
- CVE-2026-57212
RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
- Affected:
- >=3.13.0,<4.2.5
- Fixed in:
- 4.2.5
- Source:
- OSV source · Advisory
- CVE-2026-57213
RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering
- Affected:
- >=3.13.0,<4.2.5
- Fixed in:
- 4.2.5
- Source:
- OSV source · Advisory
- CVE-2026-44839
RabbitMQ: Unsanitized vhost names allow for XSS in management UI
- Affected:
- >=4.1.0,<4.1.2
- Fixed in:
- 4.1.2
- Source:
- OSV source · Advisory
Compare versions
Side-by-side view of the most relevant release lines.
Recent releases
Latest release date 2026-08-17 · 1 in last 30 days · 6 in last 90 days
- 2026-08-17
- 2026-07-23
- 2026-07-20
- 2026-07-20
- 2026-06-15
- 2026-06-15
- 2026-05-20
- 2026-05-19
- 2026-04-23
- 2026-04-23
Should I upgrade?
Current versions are supported
The preferred supported release line is RabbitMQ 4.3 (standard support).
Data coverage
- Version lines
- 11
- Concrete releases
- 205
- Supported lines
- 11
- EOL lines
- 0
- Lifecycle coverage
- 11/11
- EOL coverage
- 0/11
- Provenance coverage
- 11/11
Data freshness
Last checked = last successful upstream check. Latest source update = when upstream content last changed.
- Data last checked
- 2026-08-31
- Latest source update
- 2026-08-31
Sources
First-party and other registered sources contributing release and lifecycle facts.
- RabbitMQ GitHub Releasesfirst party · high
Official source: https://api.github.com/repos/rabbitmq/rabbitmq-server/releases
Last verified 2026-08-31
- CISA Known Exploited Vulnerabilitiesfirst party
Official source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Last checked 2026-08-31
- NVD (NIST)first party
Official source: https://nvd.nist.gov
Last checked 2026-08-31
- OSV.devfirst party
Official source: https://osv.dev
Last checked 2026-08-31
Version line directory
Complete navigation into detailed version-line pages.
Currently supported
| Version line | Status | Latest release | Released | EOL |
|---|---|---|---|---|
| 4.3 | standard supportlow | 4.3.5 | 2026-08-17 | Not officially published |
| 4.2 | standard supportlow | 4.2.9 | 2026-07-20 | Not officially published |
| 4.1 | standard supportlow | 4.1.8 | 2026-01-22 | Not officially published |
| 4.0 | standard supportlow | 4.0.9 | 2025-04-14 | Not officially published |
| 3.13 | standard supportlow | 3.13.7 | 2024-08-26 | Not officially published |
| 3.12 | standard supportlow | 3.12.14 | 2024-05-05 | Not officially published |
| 3.11 | standard supportlow | 3.11.28 | 2023-12-22 | Not officially published |
| 3.10 | standard supportlow | 3.10.25 | 2023-07-18 | Not officially published |
| 3.9 | standard supportlow | 3.9.29 | 2023-03-09 | Not officially published |
| 3.8 | standard supportlow | 3.8.35 | 2022-07-09 | Not officially published |
| 3.7 | standard supportlow | 3.7.28 | 2020-08-17 | Not officially published |
