Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-57217

Опубликовано: 10 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*
Версия от 3.13.0 (включая) до 4.2.6 (исключая)

EPSS

Процентиль: 24%
0.00321
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
redhat
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
msrc
12 дней назад

RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

CVSS3: 6.5
debian
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21 ...

github
около 1 месяца назад

Topic authorization can lead to cross-tenant routing-key bypass

EPSS

Процентиль: 24%
0.00321
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863