Skip to content

Is RabbitMQ affected due to CVE-2025-4748 and CVE-2023-45853 #14319

Closed Answered by MirahImage
graorane asked this question in Questions
Discussion options

You must be logged in to vote

Given that you're using an effected OTP version, you may be impacted by CVE-2025-4748, but you can update Erlang OTP to 27.3.4.1, which is not impacted. We would also recommend upgrading to the latest RabbitMQ patch to get the latest fixes as well. However, it is worth noting that, due to the nature of this CVE, it's only an issue if an untrusted program is using zlib via OTP. In other words, RabbitMQ or another program running on the BEAM could use zlib to access files they do not have permission to access, but assuming you trust RabbitMQ and are not running other Erlang programs, this is not really an issue.

CVE-2023-45853 is in MiniZip, not the supported core of zlib, so no, RabbitMQ i…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by michaelklishin
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants