# ANSSI flags RabbitMQ, Tanzu Valkey flaws

Published: 2026-09-07 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/d8e8165b-bb0a-5641-8d23-f657f31ea76d/anssi-flags-rabbitmq-tanzu-valkey-flaws

> ANSSI advisory lists dozens of unspecified-severity vulnerabilities in VMware/Broadcom's RabbitMQ and Tanzu for Valkey on Kubernetes, urging patching.

The French national CERT (ANSSI) issued advisory CERTFR-2026-AVI-1125 covering multiple vulnerabilities in Broadcom/VMware's open-source RabbitMQ messaging broker and Tanzu for Valkey on Kubernetes. The bulletin does not describe attack vectors, exploitability, or impact details beyond stating that the flaws could allow an attacker to trigger an unspecified security issue — the vendor has not disclosed the nature of the vulnerabilities in the referenced advisories.

Affected versions include RabbitMQ 4.0.x prior to 4.0.24, 4.1.x prior to 4.1.15, 4.2.x prior to 4.2.10, 4.3.x prior to 4.3.5, and all versions prior to 3.13.19, as well as Tanzu for Valkey on Kubernetes versions prior to 13.5.0. Over 70 CVE identifiers are referenced across six linked Broadcom security bulletins (38348–38354), spanning issue years from 2024 through 2026, suggesting this is a consolidated patch rollup rather than a single new flaw.

No indication of active exploitation, proof-of-concept availability, or threat actor involvement is provided in the advisory. Defenders running RabbitMQ or Tanzu for Valkey on Kubernetes should consult the linked Broadcom advisories for per-CVE details and apply the vendor-supplied patches to reach the fixed versions listed.

## Mentioned in this report

- Vulnerabilities: CVE-2024-11053, CVE-2024-31227, CVE-2024-31228, CVE-2024-31449, CVE-2024-46981, CVE-2024-51741, CVE-2024-7264, CVE-2024-9681, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2025-21605, CVE-2025-27151, CVE-2025-32023 (poc), CVE-2025-48367, CVE-2025-6170, CVE-2026-11856, CVE-2026-13757, CVE-2026-1965, CVE-2026-33818, CVE-2026-35469, CVE-2026-3783, CVE-2026-3784, CVE-2026-39822, CVE-2026-41989, CVE-2026-42505, CVE-2026-46600, CVE-2026-4873, CVE-2026-48864, CVE-2026-5435, CVE-2026-54369, CVE-2026-54370, CVE-2026-54572, CVE-2026-5545, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1125

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d8e8165b-bb0a-5641-8d23-f657f31ea76d/anssi-flags-rabbitmq-tanzu-valkey-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
