Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57218

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rabbitmq-serverfixed4.3.0-2package
rabbitmq-servernot-affectedtrixiepackage
rabbitmq-servernot-affectedbookwormpackage
rabbitmq-servernot-affectedbullseyepackage

Примечания

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7

  • https://github.com/rabbitmq/rabbitmq-server/pull/16092

  • https://github.com/rabbitmq/rabbitmq-server/pull/16097

  • https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4 (main)

  • https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e (v4.2.6)

EPSS

Процентиль: 45%
0.00565
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

CVSS3: 6.5
redhat
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

CVSS3: 6.5
nvd
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

github
3 месяца назад

AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure

EPSS

Процентиль: 45%
0.00565
Низкий